Impact
The vulnerability is a missing authorization flaw in the Conformer for Elementor plugin that allows an attacker to bypass incorrectly configured access control levels. An unauthenticated or improperly authorized user could gain elevated privileges within the WordPress site, enabling the creation, modification, or deletion of content, settings, or plugin configurations. This could lead to unauthorized content injection, site defacement, or further compromise.
Affected Systems
The issue affects WordPress installations that use the merkulove Conformer for Elementor plugin on any version up to and including 1.0.7. The plugin’s version range is n/a through <=1.0.7, meaning any deployment using a version in that range is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact severity. EPSS <1% shows a low likelihood of exploitation, and the vulnerability is not catalogued in CISA KEV. The likely attack path is through the web interface of the plugin, where an attacker with access to a user session or a compromised account could exploit the misconfigured access control. If the attacker can influence plugin configuration, they could grant themselves extra privileges.
OpenCVE Enrichment