Impact
The vulnerability is a missing authorization flaw in the Lottier for Elementor plugin. Because the plugin fails to enforce proper access control, an attacker who can interact with plugin endpoints can elevate privileges or perform actions that should be restricted to authorized users. This flaw is classified as CWE‑862 and could compromise the confidentiality, integrity, or availability of a site’s content and administration interfaces whenever exploited.
Affected Systems
Against the vendor merkulove, the product Lottier for Elementor is impacted. All releases from the initial version up through 1.0.9 are vulnerable, meaning that any WordPress installation running the plugin at version 1.0.9 or earlier is at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of active exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the missing authorization description, the likely attack vector involves a user with limited or no credentials gaining elevated privileges by interacting with plugin endpoints that do not validate the user’s role.
OpenCVE Enrichment