CVE Database /
CVE-2024-0516
CVE · Medium
CVE-2024-0516 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-0516
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88 |
Cross-Site Request Forgery (CSRF) |
Medium
5.3
|
< 1.3.88
|
1.3.88 |
2024-02-07 |
—
|
CVE-2024-0516
The Royal Elementor Addons and Templates plugin for WordPress contains a capability check vulnerability in the wpr_update_form_action_meta function that affects versions 1.3.87 and earlier. Unauthenticated attackers can exploit this flaw to modify post metadata without proper authorization. The vulnerability was patched in version 1.3.88.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings