Cross-Site Request Forgery in Digital Marketing and Agency Templates Addons for Elementor
CVE-2025-5938
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 June 2025
What is CVE-2025-5938?
The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks due to improper nonce validation in the import_templates() function. This vulnerability allows unauthenticated attackers to execute unauthorized actions by tricking an administrator into clicking a malicious link, potentially leading to significant security breaches. Site owners are urged to update to patched versions and implement additional security measures to mitigate the risk.
Affected Version(s)
Digital Marketing and Agency Templates Addons for Elementor * <= 1.1.1