PT-2025-40618 · WordPress · Wdesignkit

Peter Thaleikis

·

Published

2025-10-04

·

Updated

2025-10-04

·

CVE-2025-9029

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress versions through 1.2.16
Description The WDesignKit plugin for WordPress does not properly verify user authorization, allowing unauthenticated attackers to submit feedback data to external services through the wdkit handle review submission function.
Recommendations Update to a version later than 1.2.16.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9029

Affected Products

Wdesignkit