<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:netgear:dg834gv5_firmware:1.6.01.34:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3onetgeardg834gv5_firmware1.6.01.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 13:02:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3onetgeardg834gv5_firmware1.6.01.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in Royal Elementor Addons</title><link>https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-info-disclosure/</link><pubDate>Mon, 14 Sep 2026 13:02:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-info-disclosure/</guid><description>An improper access control vulnerability in the Royal Elementor Addons plugin for WordPress allows unauthenticated remote attackers to disclose sensitive configuration or user information via REST API endpoints.</description><content:encoded><![CDATA[<p>The Royal Elementor Addons plugin for WordPress contains an information disclosure vulnerability, identified as CVE-2024-4235. This vulnerability stems from improper access control checks within the plugin's REST API endpoints. An unauthenticated remote attacker can exploit this flaw by sending specifically crafted HTTP requests to these endpoints, potentially resulting in the unauthorized access to sensitive plugin configurations, site metadata, or user-related information. The vulnerability affects versions of the Royal Elementor Addons plugin prior to 1.3.79. Given the widespread use of Elementor addons in the WordPress ecosystem, defenders should audit web server logs for unauthorized access patterns directed at the plugin's API paths and prioritize patching to the latest version to remediate the flaw.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to exfiltrate sensitive site configuration details or user data, which could facilitate further reconnaissance or account takeover attacks. While the exact scope of accessible data depends on the specific site configuration, such information leaks often lead to the exposure of backend paths, plugin settings, or administrative metadata.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of the Royal Elementor Addons plugin to version 1.3.79 or later across all WordPress deployments immediately. Detection engineers should inspect web server access logs for anomalous GET requests directed at REST API routes associated with the plugin that return 200 OK statuses from unauthenticated sources.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>