Access Control Flaw in Lottier Plugin by Merkulove
CVE-2025-66167

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 December 2025

What is CVE-2025-66167?

The Lottier plugin by Merkulove contains a missing authorization vulnerability that stems from improperly configured access control security levels. This flaw can be exploited to gain unauthorized access to functionalities, potentially compromising the security of affected WordPress sites. Users of Lottier versions from n/a up to and including 1.1.1 are encouraged to evaluate their installations and apply the necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Lottier <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock | Patchstack Bug Bounty Program
.
CVE-2025-66167 : Access Control Flaw in Lottier Plugin by Merkulove