HomeDefault status
unaffected
Any version before 1.7.1037
affected
Description
The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version before 1.7.1037
Credits
Envel Le Clainche
WPScan
References
wpscan.com/...rability/b2eadb7a-30a4-44c7-a420-849484faccf4/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.