WordPress Plugin Vulnerabilities
Royal Addons for Elementor < 1.7.1050 - Unauthenticated Custom Post Type Contents Exposure
Description
The plugin is vulnerable to Information Exposure via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Quốc Huy (jtwings)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-03-16 (about 1 month ago)
Added
2026-03-16 (about 1 month ago)
Last Updated
2026-03-16 (about 1 month ago)