Back

MEDIUM

Royal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Creation

Published Jan 9, 2023

Description

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jan 9, 2023
Updated Apr 9, 2025
Reserved Nov 21, 2022
CISA Vulnrichment
Updated Apr 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a