PT-2025-32628 · WordPress · Uicore Elements

Michael Mazzolini

·

Published

2025-08-12

·

Updated

2025-08-17

·

CVE-2025-6253

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: UiCore Elements – Free Elementor widgets and templates for WordPress versions up to and including 1.3.0
Description: The plugin is susceptible to arbitrary file reading via the prepare template() function. This is due to a missing capability check and insufficient controls on the filename specified. This allows unauthenticated attackers to read the contents of arbitrary files on the server, potentially exposing sensitive information.
Recommendations: Update UiCore Elements – Free Elementor widgets and templates for WordPress to a version later than 1.3.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-6253

Affected Products

Uicore Elements