WordPress Plugin Vulnerabilities

Royal Addons for Elementor < 1.7.1050 - Unauthenticated Custom Post Type Contents Exposure

Description

The plugin is vulnerable to Information Exposure via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons.

Affects Plugins

Fixed in 1.7.1050

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Quốc Huy (jtwings)
Verified
No

Timeline

Publicly Published
2026-03-16 (about 1 month ago)
Added
2026-03-16 (about 1 month ago)
Last Updated
2026-03-16 (about 1 month ago)

Other