CVE-2024-50442 MEDIUM

CVE-2024-50442: WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability

Vendor Wp Royal
Product Royal Elementor Addons
Weakness CWE-611 · XXE
Published October 28, 2024
Last update May 11, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

What the vulnerability does

01Description

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.

Explanation of Vulnerability in Simple Terms

02Summary

Royal Elementor Addons versions up to 1.3.980 contain an XML External Entity (XXE) vulnerability that allows authenticated administrators to read sensitive files from the server or cause denial of service. The vulnerability exists in XML parsing functionality that does not properly restrict external entity resolution. An attacker with admin privileges can craft malicious XML input to extract configuration files, database credentials, or crash the application.

What an attacker can do

03Attacker Capabilities

Read sensitive server files or cause the site to become unavailable.

Potential impact on your site

04Site Impact

An admin account compromise could expose database credentials and configuration files, or disrupt site availability.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the WordPress site.

Key dates

06Disclosure timeline

October 28, 2024 CVE published
May 11, 2026 Record updated