Impact
A missing authorization flaw in the Masterstudy Elementor Widgets plugin allows an attacker to access or alter content managed by the plugin. The vulnerability arises from incorrectly configured access control layers, enabling users without proper privileges to exploit plugin functions. The result is an unauthorized escalation that can compromise site integrity, leading to potential data tampering or manipulation of widget settings.
Affected Systems
WordPress Masterstudy Elementor Widgets plugin, vendor StylemixThemes. All releases up through version 1.2.4 are affected. Installations that have not upgraded beyond 1.2.4 are exposed to this flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability is not catalogued in CISA KEV. An attacker would need to identify a backdoor or exploit the plugin’s privileged functions; a privileged user or one with sufficient role could leverage the flaw to bypass normal authorization checks. Because it depends on available user roles, the attack surface may be limited to contributors or administrators who can reach the plugin’s configuration pages.
OpenCVE Enrichment