Impact
The Searcher for Elementor plugin suffers a missing authorization flaw that allows attackers to access the plugin’s search functionality without proper authentication. This weakness, classified as CWE-862, can enable unauthorized users to retrieve content or manipulate search settings that should be restricted to privileged staff, potentially exposing sensitive site data or affecting site integrity.
Affected Systems
The vulnerability affects the WordPress Searcher for Elementor plugin developed by merkulove for all releases up to and including version 1.0.3. WordPress installations that have this plugin installed and retained at these versions are susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% reflects a very low probability of exploitation at present. The vendor has not listed this issue in the CISA KEV catalog. Attackers would likely exploit the flaw through the web interface of a WordPress site that has the vulnerable plugin enabled, using crafted requests to invoke search functions without authentication.
OpenCVE Enrichment