GHSA-v5xw-4p3j-4gfhMediumCVSS 5.3

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability...

Published
August 26, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (1)

📋 Description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.

🔗 References (3)