Executive brief
Questionar for Elementor is a WordPress plugin used to create and manage questionnaires within the Elementor page builder. A broken access control vulnerability allows unauthenticated or low-privileged users to access pages and data they should not have permission to view, potentially exposing sensitive questionnaire responses or configuration.
Technical details
The vulnerability is a broken access control issue affecting Questionar for Elementor version 1.1.7 and earlier. The plugin fails to properly validate user permissions before allowing access to certain resources or actions. An attacker with subscriber-level privileges (or potentially unauthenticated in certain configurations) can bypass access controls to view or interact with restricted questionnaire data or pages. No official patch is currently available; users are advised to update to a newer version if available or disable the plugin until a fix is released.
Affected products
- merkulove Questionar for Elementor <= 1.1.7
Timeline
- 2025-11-10: disclosed: Vulnerability reported to Patchstack
- 2025-12-31: advisory: Published by Patchstack and disclosed on NVD