Junglewise Threat Intelligence

CVE-2025-66160: Merkulove Graphist for Elementor broken access control

CVE-2025-66160 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Graphist for Elementor is a WordPress plugin that provides graphing and charting capabilities for the Elementor page builder. The plugin fails to properly enforce access controls, allowing lower-privileged users (such as subscribers) to view or access content and pages that should be restricted to higher-privilege users, potentially exposing sensitive data.

Technical details

The vulnerability is a broken access control issue in Select Graphist for Elementor plugin version 1.2.10 and earlier. The plugin fails to implement proper authorization checks when handling user requests, allowing users with lower privilege levels (e.g., subscriber role) to bypass restrictions and access functionalities or data they should not be permitted to reach. This is a server-side authorization flaw without requiring network elevation or user interaction. An attacker with a low-privilege account can exploit this to view restricted pages or perform unauthorized actions. No official patch is currently available as of the advisory publication.

Affected products

  • Merkulove Graphist for Elementor through 1.2.10

Timeline

  • 2025-11-11: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack
  • 2025-12-31: advisory: Published to NVD

References