PT-2024-14843 · WordPress · The Royal Elementor Addons/Templates
Krzysztof Zając
·
Published
2024-01-16
·
Updated
2025-06-02
·
CVE-2023-5922
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Royal Elementor Addons and Templates WordPress plugin versions prior to 1.3.81
Description
The issue allows unauthenticated users to access arbitrary draft, private, and password-protected posts/pages content. This is due to the plugin not ensuring that users accessing posts via an AJAX action have the right to do so. The REST endpoint is currently disabled in the plugin.
Recommendations
For versions prior to 1.3.81, update to version 1.3.81 or later to resolve the issue. As a temporary workaround, consider disabling the AJAX action for accessing posts until a patch is available. Restrict access to sensitive posts and pages to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Royal Elementor Addons/Templates