CVE-2025-68087
Description
Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modalier for Elementor: from n/a through <= 1.0.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Modalier for Elementor plugin <=1.0.6 has missing authorization checks, allowing unauthenticated users to exploit misconfigured access controls.
Modalier for Elementor, a WordPress plugin, versions up to and including 1.0.6, contain a missing authorization vulnerability. The plugin fails to properly validate access control security levels, resulting in a broken access control issue that can be exploited by attackers without proper privileges [1].
Exploitation requires no authentication, meaning any unauthenticated web visitor can trigger the vulnerable functionality. The attack surface is broad, as the plugin is widely deployed on WordPress sites, and this type of vulnerability is commonly used in mass-exploit campaigns targeting thousands of websites simultaneously [1].
Successful exploitation allows an attacker to perform actions normally restricted to higher-privileged users, such as modifying plugin settings or data. The CVSS v3.1 base score is 5.4 (Medium), reflecting the moderate but real risk of unauthorized access [1].
The vendor Patchedstack recommends updating the plugin immediately. Websites running an affected version should apply the available patch; if updating is not possible, site owners should contact their hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3<=1.0.6+ 1 more
- (no CPE)range: <=1.0.6
- (no CPE)range: <= 1.0.6
- Range: <= 1.0.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.