Back

LOW

Royal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Deletion

Published Jan 9, 2023

Description

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jan 9, 2023
Updated Apr 9, 2025
Reserved Nov 21, 2022
CISA Vulnrichment
Updated Apr 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a