PT-2026-4004 · Elementor+1 · Elementor+1

Published

2026-01-22

·

Updated

2026-01-25

·

CVE-2025-66135

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions merkulove Imager for Elementor versions through 2.0.4
Description An authorization issue exists in merkulove Imager for Elementor imager-elementor, allowing exploitation of incorrectly configured access control security levels. The issue relates to missing authorization checks, potentially allowing unauthorized access to resources or functionality.
Recommendations Update merkulove Imager for Elementor to a version later than 2.0.4.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-66135

Affected Products

Elementor
Merkulove Masker For Elementor