Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5922


The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content


Published

2024-01-16T16:15:13.487

Last Modified

2025-06-02T15:15:25.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application royal-elementor-addons royal_elementor_addons < 1.3.81 Yes

References