Impact
The vulnerability is a missing authorization flaw in the WordPress Select Graphist for Elementor plugin that allows an attacker to access or modify plugin data that should be restricted to authorized users. This flaw can expose configuration details, user inputs, or graphical data produced by the plugin, and may enable further exploitation of the host site. It is classified as a CWE‑862 "Missing Authorization" weakness.
Affected Systems
Any WordPress installation that has the merkulove Select Graphist for Elementor plugin version 1.2.10 or earlier is vulnerable. The issue applies to all sites using this plugin, regardless of the number of users or site structure.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation involves generating HTTP requests to the plugin’s administrative endpoints; an attacker with knowledge of the plugin’s URL structure can obtain or modify data without advanced privileges. As the flaw does not enable arbitrary code execution, the main risks are confidentiality and integrity of the plugin’s data.
OpenCVE Enrichment