Insufficient Access Control in Royal Elementor Addons for WordPress
CVE-2022-4711
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 10 January 2023
What is CVE-2022-4711?
The Royal Elementor Addons plugin for WordPress has a security weakness in its AJAX action named 'wpr_save_mega_menu_settings'. This issue permits any authenticated user, including those with minimal permissions, such as subscribers, to alter and manage Mega Menu settings across all menu items. This could lead to unauthorized changes that compromise the intended functionality and security of the website.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) * <= 1.3.59
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved