Vulnerabilities > Crowdytheme

DATE CVE VULNERABILITY TITLE RISK
2025-03-04 CVE-2025-1639 Missing Authorization vulnerability in Crowdytheme Arolax
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6.
network
low complexity
crowdytheme CWE-862
8.8