CVE Database /
CVE-2024-7417
CVE · Medium
CVE-2024-7417 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7417
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
4.3
|
< 1.3.987
|
1.3.987 |
2024-10-16 |
—
|
CVE-2024-7417
A security flaw exists within the Royal Elementor Addons and Templates plugin for WordPress, specifically in versions prior to 1.4, where a function named data_fetch can reveal sensitive information from password-protected blog entries to users with subscriber-level access or higher. This vulnerability allows authorized attackers to obtain unauthorized data. The affected functionality is present across all iterations up to version 1.3.986.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings