Impact
The vulnerability is a missing authorization check in the Worker for Elementor plugin. This flaw allows users to perform actions or view data that should be restricted, potentially leading to unauthorized content manipulation or information disclosure. The weakness is identified as CWE-862, undefined user context required for proper access control.
Affected Systems
WordPress sites using the merkulove "Worker for Elementor" plugin with any version up to and including 1.0.10 are affected. No specific build or configuration variants are listed beyond the overall version range.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. Likely attack vectors involve the WordPress web interface, where a user can send crafted requests to plugin endpoints that bypass proper role checks. Exploitation requires either an authenticated session with at least moderate privileges or a misconfigured site where access controls are broadly disabled.
OpenCVE Enrichment