WordPress Plugin Vulnerabilities

Royal Elementor Addons and Templates < 1.7.1037 - Unauthenticated Media File Upload

Description

The plugin does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

Proof of Concept

Affects Plugins

Fixed in 1.7.1037

References

Miscellaneous

Original Researcher
Envel Le Clainche
Submitter
Envel Le Clainche
Submitter website
Verified
Yes

Timeline

Publicly Published
2025-11-24 (about 1 month ago)
Added
2025-11-24 (about 1 month ago)
Last Updated
2025-11-24 (about 1 month ago)

Other