Executive brief
Headinger for Elementor is a WordPress plugin that provides page header design functionality for websites using the Elementor page builder. A broken access control vulnerability allows authenticated users with limited privileges (such as subscribers) to access or modify pages and content they should not be permitted to view or edit, potentially exposing sensitive information or allowing unauthorized modifications.
Technical details
This is a broken access control vulnerability (CWE-284) in the Headinger for Elementor WordPress plugin affecting version 1.1.4 and earlier. The vulnerability stems from inadequately configured access controls that fail to properly validate whether a user has authorization to perform specific actions. An authenticated attacker with subscriber-level privileges can exploit this to access restricted functionality or data. The attack requires only network access and valid WordPress user credentials at the subscriber level or above, with no additional user interaction needed. No official patch is currently available as of the disclosure date.
Affected products
- merkulove Headinger for Elementor <= 1.1.4
Timeline
- 2025-11-10: disclosed: Reported by Phat RiO
- 2025-12-31: advisory: Published by Patchstack