WordPress Plugin Vulnerabilities

Royal Elementor Addons < 1.7.1067 - Unauthenticated Post Meta Disclosure via 'wpr_keyword' Parameter

Description

The plugin is vulnerable to Sensitive Information Exposure via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.

Affects Plugins

Fixed in 1.7.1067

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
TarPeg007
Verified
No

Timeline

Publicly Published
2026-09-11 (about 24 days ago)
Added
2026-09-13 (about 21 days ago)
Last Updated
2026-09-13 (about 21 days ago)

Other