Royal Addons for Elementor
cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:wordpress:*:*, +1 more
- < 1.7.1037
A vulnerability exists in the Royal Addons for Elementor WordPress plugin in versions prior to 1.7.1037, where improper authorization allows unauthenticated users to upload media files. This is achieved through the wpr_addons_upload_file action.
Exploitation of this vulnerability allows for unauthorized media file uploads, which could be misused to upload malicious files or scripts that could be executed on the server.
To reproduce this vulnerability, import a template kit using the Royal Addons for Elementor plugin. After the import, open the site in a private browser window and access the browser console to retrieve the WprConfig nonce. Then, send a POST request to wp-admin/admin-ajax.php with the action set to wpr_addons_upload_file, including the nonce and the file to be uploaded. The uploaded file will be accessible in the wp-content/uploads/wpr-addons/forms directory.
Users are advised to update the Royal Addons for Elementor WordPress plugin to version 1.7.1037 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.