Missing Authorization Flaw in Restrict Elementor Widgets by Codexpert, Inc
CVE-2025-64244

4.3MEDIUM

What is CVE-2025-64244?

A missing authorization vulnerability exists in the Restrict Elementor Widgets, Columns and Sections plugin developed by Codexpert, Inc. This flaw allows attackers to exploit improperly configured access controls, potentially granting unauthorized access to restricted elements within a WordPress site. This vulnerability impacts versions of the plugin up to and including 1.12, making it essential for users to apply patches to prevent misuse and safeguard their website's integrity.

Affected Version(s)

Restrict Elementor Widgets, Columns and Sections <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MD ISMAIL | Patchstack Bug Bounty Program
.