Missing Authorization Flaw in Page Manager for Elementor by honzat
CVE-2025-53230

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 August 2025

What is CVE-2025-53230?

A missing authorization vulnerability in the Page Manager for Elementor plugin could allow unauthorized users to exploit incorrectly configured access control security levels, potentially gaining unauthorized access to sensitive features or data. This flaw affects versions from n/a up to 2.0.5, emphasizing the necessity for updated security practices and plugin maintenance.

Affected Version(s)

Page Manager for Elementor <= 2.0.5

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.