WordPress Plugin Vulnerabilities

WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder < 1.2.17 - Missing Authentication via wdkit_handle_review_submission Function

Description

The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to submit feedback data to external services.

Affects Plugins

Fixed in 1.2.17

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Peter Thaleikis
Verified
No

Timeline

Publicly Published
2025-10-03 (about 7 months ago)
Added
2025-10-03 (about 7 months ago)
Last Updated
2025-10-04 (about 7 months ago)

Other