CVE-2022-4102

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.
Configurations

Configuration 1 (hide)

cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:34

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/c177f763-0bb5-4734-ba2e-7ba816578937 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/c177f763-0bb5-4734-ba2e-7ba816578937 - Exploit, Third Party Advisory
Summary
  • (es) El complemento Royal Elementor Addons de WordPress anterior a 1.3.56 no tiene autorización y verifica CSRF al eliminar una plantilla y no garantiza que la publicación que se eliminará sea una plantilla. Esto podría permitir que cualquier usuario autenticado, como suscriptores, elimine publicaciones arbitrarias, asumiendo que conocen el slug relacionado.

27 Jun 2023, 15:35

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-09 23:15

Updated : 2024-11-21 07:34


NVD link : CVE-2022-4102

Mitre link : CVE-2022-4102

CVE.ORG link : CVE-2022-4102


JSON object : View

Products Affected

royal-elementor-addons

  • royal_elementor_addons
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization