Impact
This vulnerability is a broken access control flaw (CWE‑862) that exists in the Sliper for Elementor WordPress plugin. The flaw allows an attacker to bypass intended security restrictions, enabling unauthorized execution of privileged operations such as editing or deleting content or accessing configuration settings. The missing authorization check directly compromises the integrity and confidentiality of site data.
Affected Systems
It affects the Sliper for Elementor plugin developed by merkulove. All versions from the earliest available release up to and including 1.0.10 are vulnerable. WordPress sites that have installed or activated this plugin within that version range are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog, so there are no known large‑scale exploits yet. Based on the description, the likely attack vector is external HTTP requests to the plugin’s endpoints, which could be crafted by an unauthenticated or low‑privilege user to gain elevated privileges within the WordPress site.
OpenCVE Enrichment