CVE · Low

CVE-2022-4102 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4102 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56 Cross-Site Request Forgery (CSRF) Low 3.1 < 1.3.56 1.3.56 2022-12-15

CVE-2022-4102

The Royal Elementor Addons plugin for WordPress through version 1.3.55 contains a cross-site request forgery vulnerability affecting the wpr_delete_template and wpr_create_template functions. These functions lack proper nonce verification, allowing unauthenticated attackers to delete or create pages and posts by deceiving a site administrator into clicking a malicious link. The vulnerability was patched in version 1.3.56.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.