Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass necessary access controls and interact with the plugin’s restricted functionality. This Broken Access Control weakness (CWE-862) can enable unauthorized users to perform actions that should be limited to privileged roles, potentially exposing sensitive data or enabling broader compromise of the site. The impact is limited to the scope of the plugin’s permissions but can elevate risks if attackers gain the ability to manipulate content or configurations.
Affected Systems
The affected product is the WordPress plugin Reformer for Elementor by merkulove. All releases through version 1.0.6 are impacted, including the initial release and any intermediate versions, as the flaw exists in the authorization enforcement logic of the plugin as deployed in WordPress sites.
Risk and Exploitability
With a CVSS score of 5.4, the severity is moderate. The EPSS score is less than 1%, indicating a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would most likely exploit this weakness via web-based requests to the plugin’s endpoints, bypassing the intended role checks; the precise attack vector is inferred from the nature of the vulnerability and the typical deployment of WordPress plugins.
OpenCVE Enrichment