Headline
CVE-2022-4707: Royal Elementor Addons <= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the ‘wpr_create_mega_menu_template’ AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can trick an administrator into performing an action, such as clicking a link.
Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation
This record contains material that is subject to copyright
License: CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE’s copyright designation and this license in any such copy. Read more.
Copyright 1999-2023 The MITRE Corporation
Have information to add, or spot any errors? Contact us at [email protected] so we can make any appropriate adjustments.
Related news
WordPress Royal Elementor add-ons versions 1.3.59 and below suffer from cross site request forgery, insufficient access control, cross site scripting vulnerabilities.