CVE · High

CVE-2023-5922 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.81

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5922 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.81 Authorization Bypass Through User-Controlled Key High 7.5 < 1.3.81 1.3.81 2023-12-06

CVE-2023-5922

The Royal Addons for Elementor plugin prior to version 1.3.81 contains a broken access control flaw that allows unauthorized users to perform actions restricted to higher privilege levels due to missing authorization, authentication, or nonce token verification. This vulnerability was identified by Krzysztof Zając of CERT PL and has been resolved in version 1.3.81, which users should upgrade to immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.