CVE · Medium

CVE-2022-4710 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4710 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.60 1.3.60 2023-01-10

CVE-2022-4710

The Royal Elementor Addons plugin for WordPress contains a reflected cross-site scripting vulnerability affecting versions through 1.3.59. An unauthenticated attacker can inject malicious scripts by manipulating the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function, which fails to properly sanitize and escape user input. The vulnerability arises because the plugin relies on 'sanitize_text_field', which does not adequately prevent attribute-based XSS attacks. A victim must be tricked into clicking a malicious link for the injected script to execute in their browser.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.