Description
Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1.
Published: 2026-01-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in the Comparimager for Elementor plugin allows attackers to bypass intended access restrictions and perform unintended actions within the plugin’s scope. Because the vulnerability is related to incorrect configuration of access control security levels, compromised users may gain the ability to manipulate comparison data or inject content without proper permissions. The weakness maps to CWE-862 and can potentially impact confidentiality and integrity of content managed through the plugin.

Affected Systems

The vulnerability affects the WordPress Comparimager for Elementor plugin released by merkulove, specifically all versions from the first available release through 1.0.1. Users running any of these versions are exposed to the exploitation risk unless mitigated.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity, while the EPSS score of less than 1% points to a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves interacting with the plugin’s web interface, where an attacker—either authenticated with limited privileges or potentially unauthenticated, depending on site configuration—could exploit the missing authorization check to undertake privileged plugin operations.

Generated by OpenCVE AI on April 29, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Comparimager for Elementor to the latest version (1.0.2 or newer) to remove the access control flaw.
  • Disable or limit the plugin for users who do not need administrative access, ensuring only authorized accounts can invoke its functions.
  • Monitor site logs for unusual activity related to the plugin and review access permissions regularly to confirm that changes are enforced.

Generated by OpenCVE AI on April 29, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Thu, 29 Jan 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Merkulove
Merkulove comparimager For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Merkulove
Merkulove comparimager For Elementor
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in merkulove Comparimager for Elementor comparimager-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comparimager for Elementor: from n/a through <= 1.0.1.
Title WordPress Comparimager for Elementor plugin <= 1.0.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Merkulove Comparimager For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.852Z

Reserved: 2025-11-21T11:23:00.558Z

Link: CVE-2025-66142

cve-icon Vulnrichment

Updated: 2026-01-29T01:11:20.576Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:01.193

Modified: 2026-04-27T17:16:41.670

Link: CVE-2025-66142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:30:16Z

Weaknesses