Impact
The vulnerability is a missing authorization flaw that permits attackers to access functionality normally restricted by WordPress. By exploiting incorrectly configured access control levels, an attacker can perform privileged actions within the Logger for Elementor plugin. This flaw is classified as CWE‑862: Missing Authorization, resulting in unauthorized access to the plugin’s features and potential exposure of logged data.
Affected Systems
Affected are installations of the Logger for Elementor plugin by merkulove. Versions from n/a through 1.0.9 are vulnerable. Any WordPress site that uses the plugin before upgrade to a version higher than 1.0.9 is at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. The EPSS score of less than 1% suggests that exploit prevalence is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, accessed via exposed plugin pages, and that a basic authenticated user can trigger the flaw because WordPress authentication is required to interact with the plugin. Once accessed, an attacker can read or modify logged information.
OpenCVE Enrichment