WordPress Plugin Vulnerabilities
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder < 1.2.17 - Missing Authentication via wdkit_handle_review_submission Function
Description
The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to submit feedback data to external services.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Peter Thaleikis
Verified
No
WPVDB ID
Timeline
Publicly Published
2025-10-03 (about 7 months ago)
Added
2025-10-03 (about 7 months ago)
Last Updated
2025-10-04 (about 7 months ago)