Impact
Missing authorization in the Ally plugin allows attackers to bypass configured access control levels, exposing privileged actions to unauthorized users. The flaw is a classic Broken Access Control weakness (CWE-862). An attacker who can reach the plugin’s endpoints can perform actions intended only for higher‑privileged roles, potentially reading or modifying sensitive data or configurations within the WordPress site.
Affected Systems
Ally plugin from Elementor, affecting all installations running version 4.0.2 or earlier. The vulnerability applies to every deployment of the plugin up to and including 4.0.2, regardless of other WordPress configuration.
Risk and Exploitability
With a CVSS score of 5.3 the issue is considered medium severity. The EPSS score of less than 1% indicates a very low exploitation probability at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote web‑application access, inferred from the description that exploitation would require access to the WordPress site’s API or the ability to submit crafted requests to the plugin. If an attacker can execute the plugin’s endpoints, the broken access control could be leveraged to elevate privileges within the site.
OpenCVE Enrichment