Junglewise Threat Intelligence

CVE-2025-66148: merkulove Conformer for Elementor broken access control

CVE-2025-66148 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Conformer for Elementor is a WordPress plugin that provides form-building capabilities for the Elementor page builder. A broken access control vulnerability allows users with basic subscriber-level accounts to view or modify content they should not have permission to access, potentially exposing sensitive form data or allowing unauthorized form submissions.

Technical details

The vulnerability is a broken access control flaw in Conformer for Elementor versions up to 1.0.7, allowing users with subscriber-level privileges to bypass authorization checks and access or perform actions restricted to higher-privilege roles. The vulnerability affects functionality related to form access and data visibility. An attacker with a valid WordPress subscriber account can exploit this without additional preconditions. The fix is available in version 1.0.8 and later.

Affected products

  • merkulove Conformer for Elementor up to 1.0.7

Timeline

  • 2025-11-10: disclosed: Reported to Patchstack
  • 2025-12-31: patched: Version 1.0.8 released
  • 2025-12-31: advisory: Published on Patchstack

References