Information Disclosure Vulnerability in Royal Elementor Addons
An improper access control vulnerability in the Royal Elementor Addons plugin for WordPress allows unauthenticated remote attackers to disclose sensitive configuration or user information via REST API endpoints.
CVE search metadata
CVE search record: CVE-2024-4235. Severity: low. CVSS: 2.7. EPSS: 0.56%. KEV: no. Product: Royal Elementor Addons (< 1.3.79). Brief: Information Disclosure Vulnerability in Royal Elementor Addons. Brief link: https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-info-disclosure/
The Royal Elementor Addons plugin for WordPress contains an information disclosure vulnerability, identified as CVE-2024-4235. This vulnerability stems from improper access control checks within the plugin's REST API endpoints. An unauthenticated remote attacker can exploit this flaw by sending specifically crafted HTTP requests to these endpoints, potentially resulting in the unauthorized access to sensitive plugin configurations, site metadata, or user-related information. The vulnerability affects versions of the Royal Elementor Addons plugin prior to 1.3.79. Given the widespread use of Elementor addons in the WordPress ecosystem, defenders should audit web server logs for unauthorized access patterns directed at the plugin's API paths and prioritize patching to the latest version to remediate the flaw.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to exfiltrate sensitive site configuration details or user data, which could facilitate further reconnaissance or account takeover attacks. While the exact scope of accessible data depends on the specific site configuration, such information leaks often lead to the exposure of backend paths, plugin settings, or administrative metadata.
Recommendation
Prioritize the update of the Royal Elementor Addons plugin to version 1.3.79 or later across all WordPress deployments immediately. Detection engineers should inspect web server access logs for anomalous GET requests directed at REST API routes associated with the plugin that return 200 OK statuses from unauthenticated sources.
Immediate actions
Upgrade Royal Elementor Addons plugin to version 1.3.79 or later
Mitigations
Upgrade to Royal Elementor Addons 1.3.79
CVE-2024-4235