CVE · Medium

CVE-2022-47175 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] <= 1.3.75

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47175 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] <= 1.3.75 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.3.75 1.3.75 2023-08-22

CVE-2022-47175

The Royal Addons for Elementor plugin through version 1.3.75 contains a cross-site request forgery vulnerability because several functions including wpr_rating_dismiss_notice, wpr_rating_already_rated, and wpr_pro_features_dismiss_notice lack proper nonce verification. An unauthenticated attacker could exploit this by crafting a malicious request and convincing a site administrator to click a link, allowing the attacker to trigger these vulnerable functions without authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.