Impact
The vulnerability in the Royal Addons for Elementor WordPress plugin permits unauthenticated retrieval of rendered HTML content from private or draft Elementor templates that are referenced in non‑public navigation menu items. This occurs because the plugin’s REST API endpoint does not verify the post status of menu items or the templates they point to, enabling any visitor to gain confidential page content. The weakness is an information‑disclosure flaw (CWE‑200).
Affected Systems
WordPress installations running the Royal Addons for Elementor plugin version 1.7.1062 or earlier are affected. The problem arises from the plugin’s REST API that is exposed publicly if the site hosts private or draft templates linked to navigation menus.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability falls into the moderate severity range. The EPSS score of less than 1% indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited prevalence. The likely attack vector is remote, unauthenticated access to the REST endpoint, where any user can request the rendered HTML of shadow content without needing site credentials.
OpenCVE Enrichment