Junglewise Threat Intelligence

CVE-2025-66157: merkulove Sliper for Elementor broken access control in page access

CVE-2025-66157 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Sliper for Elementor is a WordPress plugin that integrates with the Elementor page builder. The vulnerability allows users with basic Subscriber-level accounts to access pages and perform actions they should not be authorized to perform, potentially exposing sensitive content or allowing unauthorized modifications to site functionality.

Technical details

The vulnerability is a broken access control flaw in the Sliper for Elementor WordPress plugin (versions <= 1.0.10) that fails to properly enforce authorization checks. An attacker with a Subscriber account (the lowest privilege level on WordPress) can exploit incorrectly configured access control security levels to access or modify restricted pages and functionality. No user interaction is required beyond having a basic user account. The attack is network-accessible as it targets a web plugin. As of the publication date, no official patch has been released.

Affected products

  • merkulove Sliper for Elementor through 1.0.10

Timeline

  • 2025-11-10: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack

References