Executive brief
Criptopayer for Elementor is a WordPress plugin that integrates cryptocurrency payment processing with the Elementor page builder. A broken access control flaw allows authenticated subscribers to access or modify pages and data they should not have permission to reach, potentially exposing customer payment information or sensitive site content.
Technical details
This is a broken access control vulnerability affecting Criptopayer for Elementor versions up to 1.0.1. The plugin fails to properly enforce authorization checks, allowing users with the Subscriber privilege level to access restricted functionality or data. An authenticated attacker with a subscriber account can bypass access controls to view or perform actions intended only for higher-privilege users. The vulnerability requires an existing WordPress account, limiting exploitability but remaining a material risk for multi-user sites. No official patch is currently available.
Affected products
- merkulove Criptopayer for Elementor <= 1.0.1
Timeline
- 2025-11-10: disclosed: Reported by Phat RiO
- 2025-12-31: advisory: Published by Patchstack