Thim Elementor Kit - Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
medium
Missing Authorization to Unauthenticated Private Course Disclosure vulnerability
- CVSS:
- 5.3
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Mar 16, 2026
Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course Disclosure
medium
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks on the 'thim-ekit/archive-course/get-courses' REST endpoint callback function in all versions up to, and including, 1.3.7. This makes it possible...
- CVSS:
- 5.3
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Mar 14, 2026
CVE-2026-1870 on NVD →
Thim Elementor Kit <= 1.3.3 - Authenticated (Contributor+) Insecure Direct Object Reference
medium
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level acces...
- CVSS:
- 4.3
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Dec 6, 2025
CVE-2025-67594 on NVD →
Thim Elementor Kit <= 1.2.8 - Missing Authorization
medium
The Thim Elementor Kit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- Jan 24, 2025
CVE-2025-24725 on NVD →
Thim Elementor Kit <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9.1
- Disclosed:
- Jan 6, 2025
CVE-2025-22312 on NVD →
Thim Elementor Kit <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
medium
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9.1
- Disclosed:
- May 10, 2024
CVE-2024-4329 on NVD →
Thim Elementor Kit <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...
- CVSS:
- 6.4
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- May 6, 2024
CVE-2024-34415 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database