Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-1639. PoCs published by Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2025-1639, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.
Description
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.
Exploits (2)
The repository contains functional exploit code for CVE-2025-1639, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.
This exploit automates the login process, checks for a vulnerable version of the Animation Addons for Elementor Pro plugin, extracts a security token, and installs/activates an arbitrary plugin. It leverages a missing capability check to achieve unauthorized plugin installation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H