CVE-2025-66146
MEDIUMMerkulove Logger for Elementor <1.0.9 - RCE
Title source: llmDescription
Missing Authorization vulnerability in merkulove Logger for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logger for Elementor: from n/a through 1.0.9.
Scores
CVSS v3
5.4
EPSS
0.0005
EPSS Percentile
16.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Classification
CWE
CWE-862
Status
draft
Timeline
Published
Dec 31, 2025
Tracked Since
Feb 18, 2026