Junglewise Threat Intelligence

CVE-2025-66156: Merkulove Watcher for Elementor broken access control

CVE-2025-66156 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Watcher for Elementor is a WordPress plugin that integrates page-building features with Elementor. A broken access control vulnerability in versions up to 1.0.9 allows subscribers and other authenticated users to view or modify content they should not have permission to access, potentially exposing sensitive page data or enabling unauthorized modifications.

Technical details

The vulnerability is classified as broken access control (OWASP A1), allowing authenticated users with subscriber-level privileges to bypass authorization checks and access restricted resources. The affected plugin versions up to 1.0.9 fail to properly enforce access control rules on sensitive pages or actions. An attacker with a valid WordPress account (even at subscriber level) can exploit this by directly requesting protected endpoints or pages. The Patchstack advisory notes that this is unlikely to be actively exploited in the wild; however, no official patch was available as of the publication date (31 December 2025).

Affected products

  • Merkulove Watcher for Elementor <=1.0.9

Timeline

  • 2025-11-10: disclosed: Vulnerability reported to Patchstack
  • 2025-12-31: advisory: Advisory published by Patchstack

References