QID 150634

Date Published: 2023-01-13

QID 150634: WordPress Royal Elementor Addons Plugin Prior to 1.3.60 Multiple Security Vulnerabilities

Royal Elementor addons is the most versatile, intuitive, and easy to use Popular Page Builder extension.

Royal Elementor addons contains multiple vulnerabilities:
CVE-2022-4700 : Insufficient Access Control to Theme Activation
CVE-2022-4701 : Insufficient Access Control to Plugin Activation
CVE-2022-4702 : Insufficient Access Control to Plugin Deactivation
CVE-2022-4703 : Insufficient Access Control to Import Deletion
CVE-2022-4704 : Insufficient Access Control to Template Import
CVE-2022-4705 : Insufficient Access Control to Template Activation
CVE-2022-4707 : Cross-Site Request Forgery to Menu Template creation
CVE-2022-4708 : Insufficient Access Control to Template Conditions Modification
CVE-2022-4709 : Insufficient Access Control to Template Kit Import
CVE-2022-4710 : Reflected Cross-Site Scripting
CVE-2022-4711 : Insufficient Access Control to Menu Settings Update

Affected versions:
Royal Elementor addons prior to version 1.3.60

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to Royal Elementor addons 1.3.60 or later version to remediate this vulnerability.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Royal Elementor Addons URL Logo wordpress.org/plugins/royal-elementor-addons/