Our takeCERT-Bund confirms an info disclosure flaw in WP Royal's Royal Elementor Addons that a remote unauthenticated attacker can trigger. Update the plugin.Cyber Resilience desk
Sources (1)
- cert_bund · cert_bund
What this means for you — Security leader:Update Royal Elementor Addons to the latest version immediately; the confirmed info disclosure flaw can be triggered by unauthenticated remote attackers.
What this means for you — Lean IT orgs:If you use the Royal Elementor Addons plugin for WordPress, update it now — an unauthenticated attacker can pull information from your site.
What this means for you — MSP:Check all managed WordPress sites running Royal Elementor Addons and apply the update; the vulnerability allows unauthenticated information disclosure.
What this means for you — Researcher:Confirmed info disclosure in WP Royal Royal Elementor Addons; unauthenticated remote trigger per CERT-Bund advisory WID-SEC-2026-2597.