Impact
The Digital Marketing and Agency Templates Addons for Elementor plugin is vulnerable to Cross‑Site Request Forgery through the import_templates() function, which lacks proper nonce validation. The flaw allows an unauthenticated attacker to initiate an import operation by sending a forged request. When a site administrator follows a malicious link, the request will be processed, potentially inserting arbitrary templates or other content into the site, thereby giving the attacker unauthenticated control over the site’s template repository.
Affected Systems
This vulnerability affects the WordPress plugin Digital Marketing and Agency Templates Addons for Elementor provided by ThemeBon, all releases up to and including version 1.1.1.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, with an EPSS score below 1% implying that exploitation is unlikely at present. The attacker must rely on social engineering, convincing an administrator to click a crafted link that triggers the CSRF request from the administrator’s browser. The vulnerability is not listed in the CISA KEV catalog, and no remote code execution is provided, but it enables unauthorized content manipulation.
OpenCVE Enrichment
EUVD