Lucene search

K
wpvulndbWpvulndbWPVDB-ID:0932E661-FD6C-480B-A709-C84EC7EF1DD5
HistoryJan 10, 2023 - 12:00 a.m.

Royal Elementor Addons < 1.3.60 - Subscriber+ Arbitrary Template Import

2023-01-1000:00:00
wpscan.com
8
plugin
authorisation
csrf
templates
user
subscriber
security

EPSS

0.001

Percentile

45.0%

The plugin does not have authorisation and CSRF checks when importing templates, which could allow any authenticated user, such as subscriber to perform such action

EPSS

0.001

Percentile

45.0%

Related for WPVDB-ID:0932E661-FD6C-480B-A709-C84EC7EF1DD5