CVE-2025-31046: WordPress AnyWhere Elementor Pro plugin <= 2.29 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29.
Other sources
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro anywhere-elementor-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through <= 2.29.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31046?
CVE-2025-31046 has a severity rating that indicates a serious security risk due to missing authorization and incorrect access control configurations.
How do I fix CVE-2025-31046?
You can fix CVE-2025-31046 by updating the WPvibes AnyWhere Elementor Pro plugin to a version higher than 2.29.
What types of access are affected by CVE-2025-31046?
CVE-2025-31046 affects incorrect access control security levels, allowing unauthorized actions by exploited users.
Is my website vulnerable if I am using AnyWhere Elementor Pro version 2.29 or lower?
Yes, if you are using AnyWhere Elementor Pro version 2.29 or lower, your website is vulnerable to CVE-2025-31046.
What should I do if I cannot update to a secure version for CVE-2025-31046?
If you cannot update to a secure version for CVE-2025-31046, consider disabling the plugin or implementing additional security measures until an update is possible.