Showing 9 vulnerabilities on this page for royal_elementor_addons

Signals CISA KEV Ransomware Nuclei
royal-elementor-addons vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CWE-434Oct 31, 20231 related artifact
CVSS9.8v3.1EPSS81.7%PoCs11SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-library-assistant', or 'woocommerce' plugins if they are installed on the site.

CWE-285Jan 10, 2023
CVSS4.3v3.1EPSS0.754%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.

CWE-284Jan 10, 2023
CVSS4.3v3.1EPSS0.945%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration templates, which can be chosen and imported via a separate action documented in CVE-2022-4704.

CWE-284Jan 10, 2023
CVSS4.3v3.1EPSS0.603%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed.

CWE-284Jan 10, 2023
CVSS4.3v3.1EPSS0.603%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any menu item.

CWE-284Jan 10, 2023
CVSS4.3v3.1EPSS0.688%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues.

CWE-284Jan 10, 2023
CVSS5.4v3.1EPSS0.798%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme.

CWE-284Jan 10, 2023
CVSS5.4v3.1EPSS0.818%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library.

CWE-284Jan 10, 2023
CVSS4.3v3.1EPSS0.603%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX