Filtered by vendor Royal-elementor-addons
Subscribe
Total
22 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-4102 | 1 Royal-elementor-addons | 1 Royal Elementor Addons | 2023-11-07 | N/A | 3.1 LOW |
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug. | |||||
CVE-2022-47175 | 1 Royal-elementor-addons | 1 Royal Elementor Addons | 2023-10-10 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions. |