WordPress Plugin Vulnerabilities
Royal Elementor Addons < 1.7.1067 - Unauthenticated Post Meta Disclosure via 'wpr_keyword' Parameter
Description
The plugin is vulnerable to Sensitive Information Exposure via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.
Affects Plugins
References
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
TarPeg007
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-09-11 (about 24 days ago)
Added
2026-09-13 (about 21 days ago)
Last Updated
2026-09-13 (about 21 days ago)