Unauthorized Plugin Installation Vulnerability in Animation Addons for Elementor Pro by WordPress
CVE-2025-1639
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2025
What is CVE-2025-1639?
The Animation Addons for Elementor Pro plugin presents a serious security issue due to the absence of a capability check within the install_elementor_plugin_handler() function. This vulnerability affects all versions up to and including 1.6, allowing authenticated users with Subscriber-level access or higher to install and activate any arbitrary plugins. This exploit can facilitate further attacks, particularly when Elementor is not active on the targeted website, making it crucial for administrators to implement immediate security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Animation Addons for Elementor Pro * <= 1.6
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved