Impact
This vulnerability is caused by a missing authorization check in the Uper for Elementor plugin. Because the plugin does not enforce proper access controls, an attacker can elevate privileges or modify content that should be protected. The result is that the attacker can view, add, alter or delete content on a WordPress site without the required permissions, potentially compromising the integrity of the site’s data.
Affected Systems
The Uper for Elementor plugin, developed by merkulove, is affected in all releases through version 1.0.5. Any WordPress installation using the plugin in this range is at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% suggests the probability of exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote and web‑based, requiring the attacker to interact with the WordPress admin interface or craft requests that exploit the broken access controls. Successful exploitation would give the attacker unauthorized access to modify site content and settings.
OpenCVE Enrichment