Description
Missing Authorization vulnerability in Rashid Slider Path for Elementor slider-path allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Path for Elementor: from n/a through <= 3.0.0.
Published: 2025-03-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified issue is a missing authorization flaw within the Rashid Slider Path for Elementor WordPress plugin. This flaw allows attackers to bypass deliberately configured access control levels and exploit the plugin’s functions without proper authentication. The result is potentially unauthorized access to plugin features, which can lead to the reading or alteration of content and compromise confidentiality, integrity, or availability of the site’s data. The problem is classified as CWE‑862, a classic Broken Access Control vulnerability.

Affected Systems

All deployments of the Rashid Slider Path for Elementor plugin that are at version 3.0.0 or earlier are affected. No additional version or patch information is supplied, so any installation of the plugin that remains on or before version 3.0.0 can be compromised.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level, while the EPSS score of less than 1% suggests that the probability of exploitation presently is low. The vulnerability is not listed in the CISA KEV catalog. Attackers would typically access the plugin via web-based interactions, implying a web-based attack vector. Based on the description, it can be inferred that an attacker with webpage access or capability to submit data through the plugin could manipulate privileges or bypass restrictions.

Generated by OpenCVE AI on May 1, 2026 at 03:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rashid Slider Path for Elementor to any version newer than 3.0.0 to eliminate the missing authorization flaw.
  • If an upgrade cannot be performed immediately, disable or remove the plugin from sites that do not need its functionality to reduce exposure.
  • Restrict filesystem permissions on the plugin directory so that only the web server user can write to it, limiting the risk of file‑based manipulation.

Generated by OpenCVE AI on May 1, 2026 at 03:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8827 Missing Authorization vulnerability in Rashid Slider Path for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Slider Path for Elementor: from n/a through 3.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Rashid Slider Path for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Slider Path for Elementor: from n/a through 3.0.0. Missing Authorization vulnerability in Rashid Slider Path for Elementor slider-path allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Path for Elementor: from n/a through <= 3.0.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 31 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Rashid Slider Path for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Slider Path for Elementor: from n/a through 3.0.0.
Title WordPress Slider Path for Elementor plugin <= 3.0.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:08.338Z

Reserved: 2025-03-31T10:05:11.644Z

Link: CVE-2025-31529

cve-icon Vulnrichment

Updated: 2025-03-31T15:48:40.823Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:47.003

Modified: 2026-04-23T15:27:54.470

Link: CVE-2025-31529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:15:07Z

Weaknesses