AnimateGL WordPress Plugin Missing Authorization Vulnerability in Settings Update

Vulnerability

A vulnerability exists in the AnimateGL Animations for WordPress plugin, specifically in the Elementor and Gutenberg Blocks Animations versions through 1.4.23. The issue arises from a lack of proper capability checks on the 'agl_json' AJAX action, allowing unauthorized users to modify the plugin's settings. This vulnerability could be exploited by unauthenticated attackers to make unauthorized changes to the plugin's configuration.

Impact

Exploitation of this vulnerability allows for unauthorized modification of the plugin's settings, which could lead to unintended changes in the website's animations or performance.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.