GHSA-v5xw-4p3j-4gfhMediumCVSS 5.3
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability...
🔗 CVE IDs covered (1)
📋 Description
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.