Description
Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allows Cross Site Request Forgery.This issue affects Theme Builder For Elementor: from n/a through <= 1.2.3.
Published: 2025-07-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that this vulnerability enables an attacker to perform actions on behalf of an authenticated user within the WordPress site by exploiting the Theme Builder For Elementor plugin. Because the plugin accepts state‑changing requests without proper CSRF validation, a malicious site could craft a request that the site will execute, potentially altering theme settings, deleting content or other privileged operations. The weakness is identified as CSRF, rated under CWE‑352. The CVSS score of 6.5 indicates a moderate severity level.

Affected Systems

The affected product is the BlocksWP Theme Builder For Elementor plugin for WordPress. Versions from the earliest available release up to and including 1.2.3 are vulnerable. No specific build numbers are provided beyond this upper limit.

Risk and Exploitability

The EPSS score is below 1 %, suggesting rare exploitation attempts. The vulnerability is not listed in the CISA KEV catalog, indicating a low public exploitation footprint. Based on typical CSRF mechanics, it is inferred that an attacker would need the victim to be logged into the WordPress site; thus the primary risk target is active administrators or users with elevated privileges. The CVSS base score of 6.5 reflects that an attacker could gain unauthorized capability but the attack is limited to the victim’s authenticated session, narrowing the opportunity window.

Generated by OpenCVE AI on May 2, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Theme Builder For Elementor to the latest released version.
  • Disable the plugin as a temporary measure until the patch is applied.
  • Ensure the site implements global CSRF protection, such as WordPress’ built‑in nonce checks on all state‑changing forms, and restrict the plugin’s cookie scope if possible.

Generated by OpenCVE AI on May 2, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21668 Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor allows Cross Site Request Forgery. This issue affects Theme Builder For Elementor: from n/a through 1.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor allows Cross Site Request Forgery. This issue affects Theme Builder For Elementor: from n/a through 1.2.3. Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allows Cross Site Request Forgery.This issue affects Theme Builder For Elementor: from n/a through <= 1.2.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 16 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00029}


Wed, 16 Jul 2025 10:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor allows Cross Site Request Forgery. This issue affects Theme Builder For Elementor: from n/a through 1.2.3.
Title WordPress Theme Builder For Elementor plugin <= 1.2.3 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:29.505Z

Reserved: 2025-07-16T08:51:58.889Z

Link: CVE-2025-54033

cve-icon Vulnrichment

Updated: 2025-07-16T20:00:39.499Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T11:15:30.570

Modified: 2026-04-23T15:32:44.433

Link: CVE-2025-54033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:15:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)