Executive brief
Conformer for Elementor is a WordPress plugin that provides form-building capabilities for the Elementor page builder. A broken access control vulnerability allows users with basic subscriber-level accounts to view or modify content they should not have permission to access, potentially exposing sensitive form data or allowing unauthorized form submissions.
Technical details
The vulnerability is a broken access control flaw in Conformer for Elementor versions up to 1.0.7, allowing users with subscriber-level privileges to bypass authorization checks and access or perform actions restricted to higher-privilege roles. The vulnerability affects functionality related to form access and data visibility. An attacker with a valid WordPress subscriber account can exploit this without additional preconditions. The fix is available in version 1.0.8 and later.
Affected products
- merkulove Conformer for Elementor up to 1.0.7
Timeline
- 2025-11-10: disclosed: Reported to Patchstack
- 2025-12-31: patched: Version 1.0.8 released
- 2025-12-31: advisory: Published on Patchstack