CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-24584: WordPress Ultimate Store Kit Elementor Addons plugin <= 2.3.0 - Broken Access Control vulnerability

4.3 CVSS

Description

Missing Authorization vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.3.0.

Classification

CVE ID: CVE-2025-24584

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

Affected Products

Vendor: BdThemes

Product: Ultimate Store Kit Elementor Addons

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.72% (scored less or equal to compared to others)

EPSS Date: 2025-02-25 (when was this score calculated)

References

https://patchstack.com/database/wordpress/plugin/ultimate-store-kit/vulnerability/wordpress-ultimate-store-kit-elementor-addons-plugin-2-3-0-broken-access-control-vulnerability?_s_id=cve

Timeline