Description
Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masker for Elementor: from n/a through <= 1.1.4.
Published: 2025-12-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Merkulove Masker for Elementor contains a missing authorization flaw that allows users without administrative privileges to exploit poorly configured access control levels. The defect originates from a failure to verify the caller’s role before processing privileged requests, enabling unauthorized manipulation of plugin settings or site content. As a classic broken access control vulnerability (CWE‑862), any actor that can reach the plugin’s endpoints could gain capabilities normally reserved for administrators, potentially compromising the confidentiality, integrity, or availability of the site’s data.

Affected Systems

All installations of Masker for Elementor from its initial release through version 1.1.4 are affected. The vulnerability applies to the merkulove plugin, which is a WordPress add‑on hosted on WordPress.org and commonly used to add visual masking features to Elementor. No specific WordPress core version requirements are listed, so any WordPress site running a vulnerable plugin instance is at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate baseline risk. The EPSS score, which can be interpreted as less than 1%, suggests that exploitation in the wild is currently low, and the issue is not yet catalogued in the CISA KEV database. The likely attack vector is HTTP requests to the plugin’s administrative endpoints, which are accessed through the web interface. Based on the description, it is inferred that an authenticated user with lower privileges or, in the case of an unprotected admin area, an unauthenticated attacker could exploit this flaw by sending crafted requests to modify plugin settings or content. Given the moderate severity and low exploit probability, administrators should prioritize patching or mitigating the access control gaps to prevent potential privilege escalation.

Generated by OpenCVE AI on April 29, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Masker for Elementor to a version newer than 1.1.4 that addresses the missing authorization flaw.
  • If an upgrade cannot be performed immediately, restrict access to the plugin’s administrative URLs so that only users with administrator capabilities can reach them, for example by configuring .htaccess rules or WordPress capability checks.
  • As a last resort, disable or uninstall the Masker for Elementor plugin until the vulnerability can be remediated.

Generated by OpenCVE AI on April 29, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Merkulove
Merkulove masker For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Merkulove
Merkulove masker For Elementor
Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masker for Elementor: from n/a through <= 1.1.4.
Title WordPress Masker for Elementor plugin <= 1.1.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Merkulove Masker For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:10:14.623Z

Reserved: 2025-11-21T11:23:54.907Z

Link: CVE-2025-66163

cve-icon Vulnrichment

Updated: 2025-12-16T16:47:47.617Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:15:58.547

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-66163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T13:30:12Z

Weaknesses