{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3onetgeardg834gv5_firmware1.6.01.34/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:netgear:dg834gv5_firmware:1.6.01.34:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":2.7,"id":"CVE-2024-4235"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Royal Elementor Addons (\u003c 1.3.79)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WP Royal"],"content_html":"\u003cp\u003eThe Royal Elementor Addons plugin for WordPress contains an information disclosure vulnerability, identified as CVE-2024-4235. This vulnerability stems from improper access control checks within the plugin's REST API endpoints. An unauthenticated remote attacker can exploit this flaw by sending specifically crafted HTTP requests to these endpoints, potentially resulting in the unauthorized access to sensitive plugin configurations, site metadata, or user-related information. The vulnerability affects versions of the Royal Elementor Addons plugin prior to 1.3.79. Given the widespread use of Elementor addons in the WordPress ecosystem, defenders should audit web server logs for unauthorized access patterns directed at the plugin's API paths and prioritize patching to the latest version to remediate the flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to exfiltrate sensitive site configuration details or user data, which could facilitate further reconnaissance or account takeover attacks. While the exact scope of accessible data depends on the specific site configuration, such information leaks often lead to the exposure of backend paths, plugin settings, or administrative metadata.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the Royal Elementor Addons plugin to version 1.3.79 or later across all WordPress deployments immediately. Detection engineers should inspect web server access logs for anomalous GET requests directed at REST API routes associated with the plugin that return 200 OK statuses from unauthenticated sources.\u003c/p\u003e\n","date_modified":"2026-09-14T13:02:45Z","date_published":"2026-09-14T13:02:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-info-disclosure/","summary":"An improper access control vulnerability in the Royal Elementor Addons plugin for WordPress allows unauthenticated remote attackers to disclose sensitive configuration or user information via REST API endpoints.","title":"Information Disclosure Vulnerability in Royal Elementor Addons","url":"https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:netgear:dg834gv5_firmware:1.6.01.34:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}