Impact
The Royal Addons for Elementor WordPress plugin versions prior to 1.7.1066 fails to enforce a capability or nonce check before furnishing taxonomy term data for any taxonomy specified by the caller. Consequently, unauthenticated users can retrieve the names and IDs of terms belonging to non‑public taxonomies. This flaw does not allow code execution, but it enables an attacker to discover internal taxonomy structures, which could aid in policy enumeration or further targeted attacks. The weakness is an improper access control issue, as the plugin does not restrict the data to authenticated or privileged users.
Affected Systems
WordPress sites running the "Royal Addons for Elementor" plugin, any version earlier than 1.7.1066. The vendor is listed as Unknown:Royal Addons for Elementor. No additional product or version details are supplied beyond the vulnerability threshold of 1.7.1066.
Risk and Exploitability
The CVSS score is not publicly available, and the EPSS score is not reported, so the precise risk quantification is unknown, but the vulnerability is exploitable by anyone who can access the WordPress installation externally. Because it requires no authentication or special privileges, the attack vector is straightforward: an unauthenticated HTTP request to the plugin’s taxonomy endpoint. The vulnerability is not currently tracked in the CISA KEV catalog, indicating no known widespread exploitation at this time.
OpenCVE Enrichment