Description
Missing Authorization vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animation Addons for Elementor: from n/a through <= 2.4.5.
Published: 2025-12-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerable plugin contains a missing authorization flaw that permits deletion of site content without proper checks. The type of access required (authenticated or otherwise) is not explicitly stated in the input; it is inferred that authenticated users may be able to delete content due to missing role checks, but unauthenticated access is not confirmed. This weak access control, classified as CWE-862, enables removal of posts, pages, media or other WordPress items, thereby compromising the integrity and availability of site data.

Affected Systems

The issue exists in Wealcoder Animation Addons for Elementor versions up to 2.4.5. Any WordPress installation running the plugin at or below this version range is affected. Site administrators should verify the plugin version to determine impact.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity while the EPSS score of less than 1% reflects a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by using the plugin’s delete functionality; it is inferred that an authenticated user may access this functionality due to missing role checks, but the level of authentication required is not explicitly confirmed. This broad access could lead to destructive loss of content, so a timely response is recommended.

Generated by OpenCVE AI on April 29, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Animation Addons for Elementor plugin to the latest available version that includes the fix.
  • If a new release is not yet available, apply a vendor‑supplied patch from the official resources.
  • Restrict delete capabilities so that only administrator users retain permission to delete content; remove that capability from editors and other roles.
  • As a temporary measure, disable the delete feature for non‑administrators by adjusting plugin settings or installing an access‑control plugin that blocks the delete endpoint.

Generated by OpenCVE AI on April 29, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 02 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Elementor
Elementor elementor
Wealcoder
Wealcoder animation Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Elementor
Elementor elementor
Wealcoder
Wealcoder animation Addons For Elementor
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animation Addons for Elementor: from n/a through <= 2.4.5.
Title WordPress Animation Addons for Elementor plugin <= 2.4.5 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References

Subscriptions

Elementor Elementor
Wealcoder Animation Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:18:34.669Z

Reserved: 2025-12-09T12:21:12.170Z

Link: CVE-2025-67540

cve-icon Vulnrichment

Updated: 2025-12-09T19:21:28.564Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:29.187

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-67540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:45:18Z

Weaknesses