Executive brief
Worker for WPBakery is a WordPress plugin that integrates page building capabilities with WPBakery. A broken access control vulnerability allows authenticated users (such as subscribers) to bypass permission checks and access functionality or data they should not be able to reach, potentially including administrative features or other users' content.
Technical details
This vulnerability is a broken access control issue (CWE-639) in the Worker for WPBakery WordPress plugin affecting versions up to 1.1.1. An attacker with subscriber-level privileges can exploit incorrectly configured access control mechanisms to perform actions or view pages that should be restricted to higher privilege levels. The vulnerability requires authentication to the WordPress site but no additional user interaction. An exploit allows privilege escalation within the WordPress environment, potentially enabling unauthorized access to administrative functionality or sensitive data. No official patch was available as of the advisory publication date.
Affected products
- Merkulove Worker for WPBakery <=1.1.1
Timeline
- 2025-12-31: disclosed: Published by Patchstack
- 2025-11-10: other: Reported by Phat RiO