Junglewise Threat Intelligence

CVE-2025-66146: merkulove Logger for Elementor broken access control

CVE-2025-66146 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Logger for Elementor is a WordPress plugin used to add event logging capabilities to Elementor page builder sites. A broken access control vulnerability allows users with low privileges (such as Subscribers) to access or perform actions they should not be authorized for, potentially exposing sensitive data or functionality within the site.

Technical details

This vulnerability is a broken access control issue (OWASP A1) in the Logger for Elementor WordPress plugin affecting versions through 1.0.9. The vulnerability allows authenticated users with Subscriber-level privileges to bypass authorization checks and access functionality or data restricted to higher-privilege roles. The attack requires authentication but no special network access or user interaction beyond the user's normal access to the WordPress site. An attacker can view other users' data or trigger actions outside their intended permission scope. No official patch is currently available as of the advisory publication date.

Affected products

  • merkulove Logger for Elementor through 1.0.9

Timeline

  • 2025-11-10: disclosed: Vulnerability reported to Patchstack
  • 2025-12-31: advisory: Published by Patchstack and NVD

References