Impact
The Royal Elementor Addons plugin for WordPress contains a missing authorization flaw that permits unauthorized browsing of the plugin’s administration interface. This broken access control (CWE-862) allows an attacker to read or modify plugin configuration.
Affected Systems
Any WordPress installation that employs WP Royal Royal Elementor Addons version 1.7.1056 or earlier is vulnerable. This includes all releases from the earliest available version through 1.7.1056 because the flaw is present in every iteration up to that point.
Risk and Exploitability
Exploitation would require an attacker to reach the plugin’s administration URLs, a scenario that is implicit from the missing authorization flaw. Based on the description, it is inferred that absence of proper access controls allows an attacker to read or modify the plugin’s configuration settings. The vulnerability’s impact on confidentiality and integrity of site data is potentially significant, however the actual exploitation likelihood cannot be determined from the available data, and the CVSS score is not published.
OpenCVE Enrichment