Description
The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'agl_json' AJAX action in all versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to update the plugin's settings.
Problem types
Product status
* (semver)
Timeline
| 2025-01-31: | Disclosed |
Credits
Lucio Sá
References
www.wordfence.com/...-ff36-4e3f-903b-e25951648075?source=cve
wordpress.org/plugins/animategl/