Improper access control in Royal Elementor Addons - CVE-2022-4701
Published: January 20, 2023
Royal Elementor Addons
WP Royal
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the wpr_activate_required_plugins AJAX action. A remote user can activate the contact-form-7, media-library-assistant, or woocommerce plugins if they are installed on the site.