VYPR
Medium severity5.4NVD Advisory· Published Dec 16, 2025· Updated Apr 15, 2026

CVE-2025-66147

CVE-2025-66147

Description

Missing Authorization vulnerability in merkulove Coder for Elementor coder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coder for Elementor: from n/a through <= 1.0.13.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WordPress Coder for Elementor plugin up to 1.0.13 allows unauthenticated attackers to exploit broken access controls.

Vulnerability

Details

The Coder for Elementor plugin for WordPress, versions up to and including 1.0.13, suffers from a missing authorization vulnerability. This flaw stems from incorrectly configured access control security levels, allowing exploitation of broken access controls [1].

Exploitation

Attackers can exploit this vulnerability without requiring authentication, as the missing authorization check fails to verify user privileges. This makes it possible for unauthenticated or low-privileged users to execute higher-privileged actions [1]. The vulnerability is often used in mass-exploit campaigns targeting thousands of websites simultaneously [1].

Impact

Successful exploitation enables attackers to perform unauthorized actions, such as modifying plugin settings or executing code, potentially leading to full site compromise. The CVSS v3 base score of 5.4 (Medium) reflects the moderate severity, but the ease of exploitation and potential for automated attacks increases risk [1].

Mitigation

Users are strongly advised to update the plugin to a patched version immediately. If an update is unavailable, the next best action is to contact a hosting provider or web developer to implement temporary workarounds [1]. No official patch version is specified, so users should monitor vendor channels for updates.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.