Impact
The vulnerability lies in a missing authorization check within the Grider for Elementor WordPress plugin, enabling attackers to exercise functions beyond their intended permissions. This flaw can let an attacker modify content or configuration settings that should otherwise be restricted, leading to integrity compromise and potential unauthorized data exposure.
Affected Systems
WordPress sites running the Grider for Elementor plugin version 1.0.8 or earlier are affected. The issue spans all installations of the plugin up to and including version 1.0.8, as indicated by the vendor’s affected‑range notation.
Risk and Exploitability
The CVSS score of 5.4 marks this as a moderate risk. The EPSS score of less than 1% suggests a low likelihood of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack requires access to the site’s backend interfaces; attackers can leverage the flaw by authenticating with any user account that the plugin fails to properly filter, then performing operations that should be limited to higher‑privileged users.
OpenCVE Enrichment