Junglewise Threat Intelligence

CVE-2025-66145: Merkulove Worker for WPBakery broken access control

CVE-2025-66145 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Worker for WPBakery is a WordPress plugin that integrates page building capabilities with WPBakery. A broken access control vulnerability allows authenticated users (such as subscribers) to bypass permission checks and access functionality or data they should not be able to reach, potentially including administrative features or other users' content.

Technical details

This vulnerability is a broken access control issue (CWE-639) in the Worker for WPBakery WordPress plugin affecting versions up to 1.1.1. An attacker with subscriber-level privileges can exploit incorrectly configured access control mechanisms to perform actions or view pages that should be restricted to higher privilege levels. The vulnerability requires authentication to the WordPress site but no additional user interaction. An exploit allows privilege escalation within the WordPress environment, potentially enabling unauthorized access to administrative functionality or sensitive data. No official patch was available as of the advisory publication date.

Affected products

  • Merkulove Worker for WPBakery <=1.1.1

Timeline

  • 2025-12-31: disclosed: Published by Patchstack
  • 2025-11-10: other: Reported by Phat RiO

References