Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 5
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
86 fiches
Royal Elementor Addons <= 1.3.59 – Insufficient Access Control to Template Activation
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation…
*-1.3.59
1.3.60
10/01/2023
Royal Elementor Addons <=1.3.55 – Missing Authorization to Subscriber+ Arbitrary Post Creation
The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template creation in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify…
*-1.3.55
1.3.56
15/12/2022
Royal Elementor Addons <=1.3.55 – Authenticated (Subscriber+) Arbitrary Post Deletion
The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template deletion in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify…
*-1.3.55
1.3.56
15/12/2022
Royal Elementor Addons <= 1.3.55 – Cross-Site Request Forgery
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on the wpr_delete_template and wpr_create_template functions. This makes it…
*-1.3.55
1.3.56
15/12/2022
Royal Elementor Addons <= 1.3.55 – Cross-Site Request Forgery
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated…
*-1.3.55
1.3.56
06/12/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.3.33)
1.3.33
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.