Impact
Royal Addons for Elementor plugins up to version 1.7.1066 suffer from unexplained exposure of post meta data. By sending the unfiltered 'wpr_keyword' parameter to a public AJAX endpoint, an attacker can perform character‑by‑character substring queries on the wp_postmeta table, effectively reading any stored metadata. This flaw is enabled by the plugin’s use of a freely available nonce that is injected into every frontend page that loads the widget, removing the need for authentication.
Affected Systems
Affected users are WordPress sites that have the Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin installed, with any version equal to or older than 1.7.1066.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate confidentiality risk. The EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not recorded in CISA’s KEV list. An attacker can exploit the flaw by simply sending a crafted HTTP request to the public endpoint that accepts the 'wpr_keyword' parameter; no special privileges or credentials are required, and the attacker can iterate over potential meta‑values to recover sensitive data.
OpenCVE Enrichment