CVE · Medium

CVE-2022-4705 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4705 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60 Improper Access Control Medium 4.3 < 1.3.60 1.3.60 2023-01-10

CVE-2022-4705

The Royal Elementor Addons plugin for WordPress contains an access control flaw in the 'wpr_final_settings_setup' AJAX action affecting versions 1.3.59 and earlier. Any logged-in user, even those with minimal subscriber-level access, can execute this action to complete the activation and import of preset site configuration templates. This vulnerability, when combined with the related flaw documented in CVE-2022-4704, allows low-privileged accounts to modify site settings that should be restricted to administrators. The issue was resolved in version 1.3.60.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.