CVE-2023-5922
Published: 16 January 2024
Summary
CVE-2023-5922 is a high-severity an unspecified weakness vulnerability in Royal-Elementor-Addons Royal Elementor Addons. Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 22.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-58194
Vulnerability details
The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access…
more
arbitrary draft, private and password protected posts/pages content
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.