Impact
Missing Authorization vulnerability in the merkulove Modalier for Elementor plugin allows attackers to use plugin functions without proper authorization. It is a broken access control flaw that could let unauthorized users interact with the plugin’s features.
Affected Systems
The vulnerability affects the merkulove Modalier for Elementor WordPress plugin in all releases up to and including version 1.0.6. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need some access to the WordPress administration interface or a user role with sufficient privileges to exploit this vulnerability. The exact attack vector is not detailed in the advisory.
OpenCVE Enrichment