Junglewise Threat Intelligence

CVE-2025-66151: merkulove Countdowner for Elementor broken access control

CVE-2025-66151 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

The Countdowner for Elementor WordPress plugin contains a broken access control vulnerability that allows lower-privileged users (such as subscribers) to access or perform actions they should not be permitted to. This could result in unauthorized viewing of sensitive content or unintended modifications within WordPress sites using this plugin.

Technical details

The vulnerability is a broken access control issue (CWE-639) in the Countdowner for Elementor WordPress plugin versions up to 1.0.4. The affected component fails to properly validate user permissions before allowing access to restricted pages or actions. An attacker with subscriber-level privileges can exploit this to bypass access controls and access content or perform actions intended only for higher-privilege users. The attack vector is network-based and requires authentication (subscriber account). No official patch is currently available as of the advisory date.

Affected products

  • merkulove Countdowner for Elementor through 1.0.4

Timeline

  • 2025-11-10: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack

References