Impact
The vulnerability resides in the Spoter for Elementor plugin and represents a missing authorization flaw that allows an attacker to exploit incorrectly configured access control settings. This flaw can enable actions that should be restricted to privileged users, such as modifying plugin configurations or accessing sensitive site data. The primary impact is therefore the potential for unauthorized access and privilege escalation rather than remote code execution.
Affected Systems
The affected product is Spoter for Elementor from the vendor merkulove. Versions from the earliest releases up to and including 1.04 are vulnerable. WordPress sites that have the plugin installed in any of those versions are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates the vulnerability is of moderate severity. With an EPSS score of less than 1 %, the likelihood of exploitation is low, and the vulnerability is not listed in CISA's KEV database. The likely attack vector is through the plugin’s web interface, where an attacker could submit requests that bypass the required authorization checks.
OpenCVE Enrichment