PT-2024-15854 · WordPress · The Royal Elementor Kit

Sean Murphy

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-0835

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Royal Elementor Kit theme for WordPress versions up to, and including, 1.0.116
Description The issue arises from a missing capability check on the dismissed handler function, allowing authenticated attackers with subscriber access or higher to update arbitrary transients to true.
Recommendations For versions up to, and including, 1.0.116, update to a version higher than 1.0.116 to resolve the issue. As a temporary workaround, consider restricting access to the dismissed handler function to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0835

Affected Products

The Royal Elementor Kit