CVE-2025-1639

HIGH

Crowdytheme Arolax < 1.7 - Missing Authorization

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-1639. PoCs published by Boshe99, Nxploited.

AI-analyzed exploit summary The repository contains functional exploit code for CVE-2025-1639, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.

Description

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.

Exploits (2)

github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-1639

The repository contains functional exploit code for CVE-2025-1639, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: Target URL · Malicious file to upload
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2025-1639

This exploit automates the login process, checks for a vulnerable version of the Animation Addons for Elementor Pro plugin, extracts a security token, and installs/activates an arbitrary plugin. It leverages a missing capability check to achieve unauthorized plugin installation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Animation Addons for Elementor Pro plugin for WordPress up to and including version 1.6.0
Auth required
Prerequisites: Valid WordPress credentials (Subscriber-level access or higher) · Target site running a vulnerable version of the plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0091
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
crowdyTheme/Animation Addons for Elementor Pro < 1.6
crowdytheme/arolax < 1.7
Published Mar 04, 2025
Tracked Since Feb 18, 2026