The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to submit feedback data to external services.
We have discovered 282 live websites that are affected by CVE-2025-9029.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 282 live websites (96% of Wdesignkit install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 7 versions ( 39% of all versions) |
| 65 websites | |
| 22 websites | |
| 14 websites | |
| 14 websites | |
| 13 websites | |
| 12 websites | |
| 11 websites | |
| 10 websites | |
| 9 websites | |
| 9 websites |
| .com | 113 websites |
| .de | 15 websites |
| .org | 12 websites |
| .net | 9 websites |
| .es | 7 websites |
| .nl | 7 websites |
| .com.au | 7 websites |
| .com.br | 7 websites |
| .it | 6 websites |
| .fr | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| *********.com | ***,*** | ||
| ***.it | ***,*** | ||
| ********.nl | ***,*** | ||
| **************.com | ***,*** | ||
| **************.net | ***,*** | ||
| *************.com | *,***,*** | ||
| **********.**.mz | *,***,*** | ||
| ****************.com | *,***,*** | ||
| *******************.de | *,***,*** |
FAQ