Back

MEDIUM

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation

Published Jan 10, 2023

Description

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jan 10, 2023
Updated Apr 8, 2026
Reserved Dec 23, 2022
CISA Vulnrichment
Updated Jan 13, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Jan 10, 2023
Updated Apr 8, 2026
Exploited since n/a
EUVD-2022-52014