Impact
The Royal Addons for Elementor WordPress plugin versions prior to 1.7.1066 fails to enforce a capability or nonce check before furnishing taxonomy term data for any taxonomy specified by the caller. Consequently, unauthenticated users can retrieve the names and IDs of terms belonging to non‑public taxonomies. This flaw does not allow code execution, but it enables an attacker to discover internal taxonomy structures, which could aid in policy enumeration or further targeted attacks. The weakness is an improper access control issue, as the plugin does not restrict the data to authenticated or privileged users.
Affected Systems
WordPress sites running the "Royal Addons for Elementor" plugin, any version earlier than 1.7.1066. The vendor is listed as Unknown:Royal Addons for Elementor. No additional product or version details are supplied beyond the vulnerability threshold of 1.7.1066.
Risk and Exploitability
The CVSS score of 5.3 and the EPSS score of less than 1% suggest moderate risk with a low probability of exploitation. The vulnerability is exploitable by anyone who can access the WordPress installation externally. Based on the description, it is inferred that the attack vector is an unauthenticated HTTP request to the plugin’s taxonomy endpoint. The vulnerability is not currently tracked in the CISA KEV catalog, indicating no known widespread exploitation at this time.
OpenCVE Enrichment