Impact
The vulnerability is a missing authorization flaw that permits users without proper privileges to access or modify core configuration settings of the Criptopayer for Elementor plugin. This incorrect access control could allow an attacker to read, alter, or delete plugin data, potentially exposing sensitive information or disrupting site functionality. The weakness corresponds to the standard Access Control vulnerability (CWE-862).
Affected Systems
The vendor merkulove, product Criptopayer for Elementor, is affected for all releases up to and including version 1.0.1. No other products or versions are explicitly mentioned.
Risk and Exploitability
With a CVSS score of 5.4, the severity is considered medium. The EPSS value of less than 1% suggests a low probability of exploitation at any given time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote, where an unauthenticated or non‑privileged web user could send crafted HTTP requests to the plugin’s endpoints to bypass access checks.
OpenCVE Enrichment