CVE-2025-24725: WordPress Thim Elementor Kit Plugin <= 1.2.8 - Broken Access Control vulnerability
Published Jan 24, 2025
·Updated
Missing Authorization vulnerability in ThimPress Thim Elementor Kit thim-elementor-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thim Elementor Kit: from n/a through <= 1.2.8.
Affected Software
1 affected component
thimpress Thim Elementor Kit<=1.2.8
Remediation
Information
Update the WordPress Thim Elementor Kit wordpress plugin to the latest available version (at least 1.2.9).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24725?
CVE-2025-24725 is a Missing Authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control levels.
2
How do I fix CVE-2025-24725?
To fix CVE-2025-24725, update the Thim Elementor Kit to the latest version beyond 1.2.8 where the vulnerability is patched.
3
Which versions of Thim Elementor Kit are affected by CVE-2025-24725?
CVE-2025-24725 affects all versions of Thim Elementor Kit up to and including version 1.2.8.
4
What type of vulnerability is CVE-2025-24725?
CVE-2025-24725 is categorized as a Missing Authorization vulnerability.
5
Can CVE-2025-24725 affect users of WordPress?
Yes, CVE-2025-24725 affects users of the Thim Elementor Kit plugin for WordPress.