Description
Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audier For Elementor: from n/a through <= 1.0.9.
Published: 2026-01-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to bypass intended access controls within the Audier For Elementor WordPress plugin. This broken access control (CWE‑862) can enable unauthorized users to execute actions that should be restricted, potentially escalating privileges within the plugin's functionality. The impact is limited to the scope of the plugin and any WordPress features it exposes, as the description does not indicate broader system compromise.

Affected Systems

WordPress sites running the merkulove Audier For Elementor plugin through version 1.0.9 are affected. The plugin is distributed as a WordPress add‑on and is available for installation on any site that has not upgraded beyond the specified version.

Risk and Exploitability

The CVSS score of 5.4 classifies this as a moderate‑severity issue, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would occur by sending crafted HTTP requests to the plugin’s endpoints, assuming the site is publicly accessible and the attacker can discover the plugin’s URL structure. The actual attack vector is inferred from the nature of the broken access control; the CVE description does not provide explicit details of how the flaw is accessed, so defenders should assume the possibility of remote exploitation via the web interface.

Generated by OpenCVE AI on April 29, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Audier For Elementor plugin to the latest available release that addresses the broken access control flaw
  • If an update is not immediately possible, disable the plugin on all non‑essential sites or restrict its use to trusted administrators only
  • Monitor the site for anomalous activity within the plugin’s administrative functions and log all access attempts

Generated by OpenCVE AI on April 29, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Thu, 29 Jan 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Merkulove
Merkulove audier For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Merkulove
Merkulove audier For Elementor
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in merkulove Audier For Elementor audier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Audier For Elementor: from n/a through <= 1.0.9.
Title WordPress Audier For Elementor plugin <= 1.0.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Merkulove Audier For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.850Z

Reserved: 2025-11-21T11:23:00.558Z

Link: CVE-2025-66139

cve-icon Vulnrichment

Updated: 2026-01-29T01:08:40.994Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:00.837

Modified: 2026-04-27T18:16:37.920

Link: CVE-2025-66139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:30:16Z

Weaknesses