Description
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Patch
AI Analysis

Impact

Royal Addons for Elementor plugins up to version 1.7.1066 suffer from unexplained exposure of post meta data. By sending the unfiltered 'wpr_keyword' parameter to a public AJAX endpoint, an attacker can perform character‑by‑character substring queries on the wp_postmeta table, effectively reading any stored metadata. This flaw is enabled by the plugin’s use of a freely available nonce that is injected into every frontend page that loads the widget, removing the need for authentication.

Affected Systems

Affected users are WordPress sites that have the Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin installed, with any version equal to or older than 1.7.1066.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate confidentiality risk. The EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not recorded in CISA’s KEV list. An attacker can exploit the flaw by simply sending a crafted HTTP request to the public endpoint that accepts the 'wpr_keyword' parameter; no special privileges or credentials are required, and the attacker can iterate over potential meta‑values to recover sensitive data.

Generated by OpenCVE AI on September 15, 2026 at 18:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Royal Addons for Elementor to any version above 1.7.1066.
  • Remove or block the wpr_keyword AJAX endpoint so that unauthenticated requests cannot reach it.
  • Adjust the plugin so that the nonce is no longer exposed via wp_localize_script, or enforce authentication for AJAX calls that rely on the nonce.

Generated by OpenCVE AI on September 15, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wproyal
Wproyal royal Addons For Elementor – Addons And Templates Kit For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wproyal
Wproyal royal Addons For Elementor – Addons And Templates Kit For Elementor

Sat, 12 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.
Title Royal Addons for Elementor <= 1.7.1066 - Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wproyal Royal Addons For Elementor – Addons And Templates Kit For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-14T18:31:41.057Z

Reserved: 2026-07-27T15:57:56.711Z

Link: CVE-2026-17585

cve-icon Vulnrichment

Updated: 2026-09-14T18:30:42.364Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T08:16:23.950

Modified: 2026-09-14T19:17:15.150

Link: CVE-2026-17585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor