Impact
Missing Authorization in the merkulove Watcher for Elementor plugin allows a user with valid credentials to exploit incorrectly configured access control and perform actions that should be restricted, potentially compromising site content, user data, and administrative settings. The flaw is a broken access control weakness (CWE‑862). Based on the description, it is inferred that attackers can use the plugin’s exposed endpoints, requiring authenticated web access, to gain unauthorized privileges.
Affected Systems
All WordPress installations running merkulove Watcher for Elementor version 1.0.9 or earlier are affected; no information about older or newer release fixes is provided.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers are inferred to need authenticated web access; they can use the plugin’s exposed endpoints to gain unauthorized privileges.
OpenCVE Enrichment