Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control settings in the Coder for Elementor plugin. This can enable the attacker to perform actions such as modifying, adding, or deleting plugin components or configurations that should be restricted. The flaw is classified as CWE‑862 – Missing Authorization, indicating that the plugin fails to verify whether a user has permission to perform certain operations.
Affected Systems
The affected product is the WordPress Coder for Elementor plugin from merkulove. All versions from the initial release through and including 1.0.13 are impacted. No specific sub‑versions are listed beyond the maximum version.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity level. The EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires a user who can authenticate to the WordPress site; the attacker would target the plugin’s management interface to gain unauthorized control. The impact is confined to the scope of the WordPress site in which the plugin is installed, potentially compromising site configuration and content integrity.
OpenCVE Enrichment