What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.
Explanation of Vulnerability in Simple Terms
Royal Elementor Addons versions up to 1.3.93 contain an integrity vulnerability allowing network-based attackers to modify data without authentication. The vulnerability requires no user interaction and affects the plugin's core functionality. Site administrators should update to a version newer than 1.3.93 to remediate the issue.
What an attacker can do
Modify plugin data or settings without logging in.
Potential impact on your site
Attackers can alter plugin configuration, content, or functionality without your knowledge or permission.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities