CVE-2022-4705
The Royal Elementor Addons plugin for WordPress contains an access control flaw in the 'wpr_final_settings_setup' AJAX action affecting versions 1.3.59 and earlier. Any logged-in user, even those with minimal subscriber-level access, can execute this action to complete the activation and import of preset site configuration templates. This vulnerability, when combined with the related flaw documented in CVE-2022-4704, allows low-privileged accounts to modify site settings that should be restricted to administrators. The issue was resolved in version 1.3.60.
Based on public CVE data (MITRE/NVD).