CVE · Medium

CVE-2022-4103 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4103 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.3.56 1.3.56 2022-12-15

CVE-2022-4103

Royal Addons for Elementor versions up to 1.3.55 contains an authorization bypass vulnerability in the wpr_create_template function that allows authenticated users with subscriber-level access or higher to create arbitrary posts and pages. The flaw stems from missing capability verification during template creation and a failure to validate that the created post is actually a template. This vulnerability enables low-privileged attackers to generate unauthorized content on the website.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.