Impact
This vulnerability is a missing authorization flaw in the Motionger for Elementor plugin. Because the plugin does not enforce proper access control, a malicious actor can gain unauthorized access to protected operations, potentially modifying or disclosing content that should be restricted.
Affected Systems
The plugin Merkulevo Motionger for Elementor, any version up to and including 2.0.4, is affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in CISA's KEV catalog. The exploit is inferred to target the web interface, where an attacker can attempt unauthorized actions if access controls are not properly enforced. No public exploitation code is known at this time.
OpenCVE Enrichment