CVE-2022-4708

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:35

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/royal-elementor-addons/trunk/admin/includes/wpr-templates-actions.php?rev=2834217 - Third Party Advisory () https://plugins.trac.wordpress.org/browser/royal-elementor-addons/trunk/admin/includes/wpr-templates-actions.php?rev=2834217 - Third Party Advisory
References () https://www.wordfence.com/blog/2023/01/eleven-vulnerabilities-patched-in-royal-elementor-addons/ - Third Party Advisory () https://www.wordfence.com/blog/2023/01/eleven-vulnerabilities-patched-in-royal-elementor-addons/ - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b3e12653-ddfe-4e02-9d9e-0263b9f71def - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/b3e12653-ddfe-4e02-9d9e-0263b9f71def - Third Party Advisory
Summary
  • (es) El complemento Royal Elementor Addons para WordPress es vulnerable a un control de acceso insuficiente en la acción AJAX 'wpr_save_template_conditions' en versiones hasta la 1.3.59 incluida. Esto permite que cualquier usuario autenticado, incluidos aquellos con permisos de nivel de suscriptor, modifique las condiciones bajo las cuales se muestran las plantillas.
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.3

11 Jul 2023, 14:51

Type Values Removed Values Added
CWE CWE-284 NVD-CWE-Other

Information

Published : 2023-01-10 17:15

Updated : 2024-11-21 07:35


NVD link : CVE-2022-4708

Mitre link : CVE-2022-4708

CVE.ORG link : CVE-2022-4708


JSON object : View

Products Affected

royal-elementor-addons

  • royal_elementor_addons