Junglewise Threat Intelligence

CVE-2025-66144: merkulove Worker for Elementor broken access control

CVE-2025-66144 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Worker for Elementor is a WordPress plugin that extends the Elementor page builder. A broken access control vulnerability allows authenticated users with limited privileges (such as Subscribers) to access or perform actions they should not have permission to perform, including viewing other users' data or content. This could lead to unauthorized information disclosure or account compromise on affected WordPress sites.

Technical details

The vulnerability is a broken access control issue in Worker for Elementor versions up to and including 1.0.10. The plugin fails to properly enforce authorization checks on sensitive actions or data endpoints. An authenticated attacker with Subscriber-level privileges can exploit this misconfiguration to bypass access controls and view or manipulate resources restricted to higher-privilege users. The vulnerability requires user authentication but no special interaction; exploitation is straightforward for any logged-in attacker. No official patch is currently available as of the advisory publication date.

Affected products

  • merkulove Worker for Elementor <= 1.0.10

Timeline

  • 2025-11-10: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack

References