Cross-Site Request Forgery in Digital Marketing and Agency Templates Addons for Elementor
CVE-2025-5938

5.3MEDIUM

What is CVE-2025-5938?

The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks due to improper nonce validation in the import_templates() function. This vulnerability allows unauthenticated attackers to execute unauthorized actions by tricking an administrator into clicking a malicious link, potentially leading to significant security breaches. Site owners are urged to update to patched versions and implement additional security measures to mitigate the risk.

Affected Version(s)

Digital Marketing and Agency Templates Addons for Elementor * <= 1.1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.
CVE-2025-5938 : Cross-Site Request Forgery in Digital Marketing and Agency Templates Addons for Elementor