Executive brief
Live Copy Paste for Elementor is a WordPress plugin that allows users to copy and paste design elements between different websites. A security flaw in versions up to 1.5.3 allows users with low-level 'Contributor' accounts to perform actions or access data they should not be authorized to see. This could lead to unauthorized information disclosure or minor unauthorized changes to site content.
Technical details
A broken access control vulnerability exists in the Live Copy Paste for Elementor plugin (versions <= 1.5.3) due to missing authorization checks (CWE-862). The flaw allows an authenticated attacker with 'Contributor' level privileges to execute functions or access data that should be restricted to higher-privileged users. The attack is performed over the network without requiring user interaction. While the CVSS score is 4.3 (Medium), the impact is primarily limited to unauthorized data access (Confidentiality: Low). As of the advisory date, no official patch has been confirmed.
Affected products
- bdthemes Live Copy Paste for Elementor <= 1.5.3
Timeline
- 2025-10-23: disclosed: Reported by MD ISMAIL
- 2026-06-26: advisory: Published by Patchstack and NVD