CVE-2025-64211
Description
Missing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Masterstudy Elementor Widgets ≤1.2.4 allows unauthenticated access to restricted functions; update to 1.2.5 fixed.
CVE-2025-64211 is a missing authorization vulnerability in the Masterstudy Elementor Widgets plugin for WordPress, affecting versions up to and including 1.2.4. The flaw arises because the plugin fails to properly enforce access controls on certain functionality, allowing users to access actions that should be restricted by ACLs [1].
An attacker can exploit this vulnerability without authentication by sending specially crafted requests to the affected plugin's endpoints. Since no valid nonce or capability check is performed, any unauthenticated visitor can trigger privileged operations that were intended only for authenticated users with higher roles [1].
The impact is that an attacker can access functionality not properly constrained by ACLs, which may include administrative actions such as modifying content or settings, depending on the specific exposed functions. While the CVSS score is 5.3 (Medium), the vendor has assessed the severity as low and considers exploitation unlikely [1].
The vulnerability has been addressed in version 1.2.5 of the plugin. Users are strongly advised to update immediately. If automatic updates are enabled via Patchstack or another solution, the fix can be applied seamlessly. Website administrators unable to update should consult their hosting provider for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 1.2.4+ 1 more
- (no CPE)range: <= 1.2.4
- (no CPE)range: <=1.2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.