royal-elementor-addons Vulnerabilities and Affected Products
Vulnerabilities associated with royal_elementor_addons.
Products
Clear product- royal_elementor_addons9 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-5360CRITICAL | Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File UploadThe Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE. | CVSS9.8v3.1 | EPSS81.7% | PoCs11 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-4701MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin ActivationThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-library-assistant', or 'woocommerce' plugins if they are installed on the site. CWE-285Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.754% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4703MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import DeletionThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data. CWE-284Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.945% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4705MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template ActivationThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration templates, which can be chosen and imported via a separate action documented in CVE-2022-4704. CWE-284Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.603% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4708MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions ModificationThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed. CWE-284Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.603% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4711MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings UpdateThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any menu item. CWE-284Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.688% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4702MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin DeactivationThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues. CWE-284Jan 10, 2023 | CVSS5.4v3.1 | EPSS0.798% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4700MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme ActivationThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme. CWE-284Jan 10, 2023 | CVSS5.4v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4709MEDIUM | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit ImportThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library. CWE-284Jan 10, 2023 | CVSS4.3v3.1 | EPSS0.603% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |