Vulnerabilities > CVE-2024-0835 - Missing Authorization vulnerability in Royal-Elementor-Addons Royal Elementor KIT

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
royal-elementor-addons
CWE-862

Summary

The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in all versions up to, and including, 1.0.116. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary transients. Note, that these transients can only be updated to true and not arbitrary values.

Vulnerable Configurations

Part Description Count
Application
Royal-Elementor-Addons
36

Common Weakness Enumeration (CWE)