Access Control Flaw in Lottier Plugin by Merkulove
CVE-2025-66167
Currently unrated
What is CVE-2025-66167?
The Lottier plugin by Merkulove contains a missing authorization vulnerability that stems from improperly configured access control security levels. This flaw can be exploited to gain unauthorized access to functionalities, potentially compromising the security of affected WordPress sites. Users of Lottier versions from n/a up to and including 1.1.1 are encouraged to evaluate their installations and apply the necessary updates to mitigate risks associated with this vulnerability.
Affected Version(s)
Lottier <= n/a