
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66137 is a Missing Authorization (Broken Access Control) vulnerability in the Searcher for Elementor WordPress plugin developed by merkulove. It allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels, gaining unauthorized access to restricted functionality. The vulnerability affects all versions of the plugin up to and including 1.0.3. It was published on January 22, 2026, with a CVSS v3.1 base score of 8.8 (High) (Feedly).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to sensitive functionality or data. This is a network-accessible vulnerability requiring only low privileges and no user interaction, making it straightforward to exploit from any authenticated session. The attack vector is entirely remote, with low complexity, meaning an attacker simply needs a valid low-privilege WordPress account (e.g., subscriber) to trigger the flaw (Feedly).
Successful exploitation could allow a low-privileged authenticated attacker to gain unauthorized access to restricted plugin functionality, potentially resulting in unauthorized modification of plugin settings, data manipulation, and disclosure of confidential information. Given the high confidentiality, integrity, and availability impact scores, a successful attack could compromise sensitive site data, alter site behavior, or disrupt availability of the affected WordPress installation (Feedly).
There is currently no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is very low at 0.017%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
wp-admin/admin-ajax.php) with actions associated with the Searcher for Elementor plugin.searcher-elementor.wp-admin/admin-ajax.php or REST API endpoints from subscriber-level accounts targeting Searcher for Elementor plugin actions.The primary remediation is to update the Searcher for Elementor plugin to a version newer than 1.0.3 if a patched release becomes available from the vendor (merkulove). Until a patch is released, site administrators should consider temporarily disabling the plugin if it is not critical to operations. Additional mitigations include auditing and restricting low-privilege user role capabilities, implementing additional access control at the application or WAF level, and monitoring for suspicious plugin activity or unauthorized configuration changes (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."