Executive brief
Walker for Elementor is a WordPress plugin that extends page-building functionality. The plugin contains a broken access control vulnerability allowing users to view or perform actions on pages they shouldn't have permission to access, such as viewing other users' data or making unauthorized modifications.
Technical details
This is a broken access control vulnerability (CWE-284) in Walker for Elementor plugin versions through 1.1.6. The vulnerability allows authenticated users with low privilege levels (e.g., subscribers) to bypass access control checks and access resources or perform actions they should not be permitted to perform. The vulnerability appears to stem from improper authorization checks in the plugin code. Exploitation requires user authentication but no additional prerequisites. An attacker can access other users' data or perform administrative actions without proper authorization. No official patch was available as of the publication date.
Affected products
- merkulove Walker for Elementor through 1.1.6
Timeline
- 2025-11-10: disclosed: Reported to Patchstack
- 2025-12-31: advisory: Published by Patchstack and NVD