Description
Missing Authorization vulnerability in Spider Themes Spider Elements spider-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spider Elements: from n/a through <= 1.6.6.
Published: 2025-04-10
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from a missing authorization check in the Spider Elements plugin developed by Spider Themes, allowing an attacker to exploit incorrectly configured access control security settings. The flaw is classified as CWE-862 and can enable an unauthorized user to perform privileged operations that should otherwise be restricted, such as modifying plugin options or accessing sensitive configuration data. While the description does not specify code execution, the potential for unauthorized configuration changes threatens the integrity of the WordPress site and could serve as a foothold for further exploitation.

Affected Systems

The affected product is the WordPress plugin Spider Elements from Spider Themes. All releases up to and including version 1.6.6 are vulnerable. Administrators or developers who have installed these versions should verify the plugin version and consider updating.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation time‑of‑arrival. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote via the WordPress web interface, where an attacker could submit privileged requests through the plugin’s admin pages or API endpoints. No additional prerequisites such as remote code execution are described, but the absence of proper access control could be combined with other vulnerabilities to increase impact.

Generated by OpenCVE AI on April 30, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spider Elements to the latest available release that contains the access control fix.
  • Restrict the plugin’s administrative interface by hardening WordPress roles so that only trusted Administrators can configure or access the plugin settings.
  • Continuously monitor and audit configuration changes made through Spider Elements and log any unauthorized activity to detect potential abuse.

Generated by OpenCVE AI on April 30, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10452 Missing Authorization vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2. Missing Authorization vulnerability in Spider Themes Spider Elements spider-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spider Elements: from n/a through <= 1.6.6.
Title WordPress Spider Elements – Addons for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability WordPress Spider Elements – Addons for Elementor plugin <= 1.6.6 - Broken Access Control vulnerability
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Thu, 10 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2.
Title WordPress Spider Elements – Addons for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.149Z

Reserved: 2025-04-04T10:01:42.464Z

Link: CVE-2025-32216

cve-icon Vulnrichment

Updated: 2025-04-10T19:05:51.268Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T08:15:18.967

Modified: 2026-04-23T15:28:46.410

Link: CVE-2025-32216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:30:03Z

Weaknesses