Access Control Weakness in Modalier for Elementor by merkulove
CVE-2025-68087

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 December 2025

What is CVE-2025-68087?

A missing authorization vulnerability was identified in the Modalier for Elementor plugin by merkulove, allowing attackers to exploit incorrectly configured access control levels. This security loophole poses a risk of unauthorized access to functionalities within the plugin, particularly affecting versions up to 1.0.6. Administrators using this plugin should review their configurations and apply necessary updates to mitigate potential exploits.

Affected Version(s)

Modalier for Elementor <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock | Patchstack Bug Bounty Program
.
CVE-2025-68087 : Access Control Weakness in Modalier for Elementor by merkulove