What the vulnerability does
01Description
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.
Explanation of Vulnerability in Simple Terms
02Summary
Royal Elementor Addons versions up to 1.3.980 contain an XML External Entity (XXE) vulnerability that allows authenticated administrators to read sensitive files from the server or cause denial of service. The vulnerability exists in XML parsing functionality that does not properly restrict external entity resolution. An attacker with admin privileges can craft malicious XML input to extract configuration files, database credentials, or crash the application.
What an attacker can do
03Attacker Capabilities
Read sensitive server files or cause the site to become unavailable.
Potential impact on your site
04Site Impact
An admin account compromise could expose database credentials and configuration files, or disrupt site availability.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
October 28, 2024
CVE published
May 11, 2026
Record updated