CVE-2025-9029

WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function

The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to missing authorization via the wdkit_handle_review_submission function in versions less than, or equal to, 1.2.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to submit feedback data to external services.


We have discovered 282 live websites that are affected by CVE-2025-9029.

Run a Free Instant Scan




Affected Software

Product  Wdesignkit
Category Wordpress Plugins
Vulnerable Domains282 live websites (96% of Wdesignkit install base)
Vulnerable Versions
  • from 0 through 1.2.16
Vulnerable Versions Count7 versions ( 39% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Oct 4, 2025
  • Updated - Apr 8, 2026

Credits

  • Peter Thaleikis (finder)

Website Distribution by Country

Number of websites using CVE-2025-9029
United States65 websites



Germany22 websites
India14 websites
Spain14 websites
South Africa13 websites
GB12 websites
France11 websites
Cyprus10 websites
Italy9 websites
Iran9 websites

Website Distribution by TLD

Number of websites using CVE-2025-9029
.com113 websites
.de15 websites
.org12 websites
.net9 websites
.es7 websites
.nl7 websites
.com.au7 websites
.com.br7 websites
.it6 websites
.fr5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-9029

Top websites that are affected by CVE-2025-9029. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States***,***
*********.com Canada***,***
***.it Italy***,***
********.nl Netherlands***,***
**************.com GB***,***
**************.net United States***,***
*************.com United States*,***,***
**********.**.mz Mozambique*,***,***
****************.com United States*,***,***
*******************.de Germany*,***,***
See full domain list

FAQ

CVE-2025-9029 is Missing Authorization in Wdesignkit
A total of 282 websites have been identified as vulnerable to CVE-2025-9029, based on global website indexing conducted by WebTechSurvey.
The Wdesignkit is affected by the CVE-2025-9029 vulnerability.
Wdesignkit versions up to and including 1.2.16 are vulnerable to CVE-2025-9029.