Royal Elementor Kit <= 1.0.116 - Missing Authorization to Arbitrary Transient Update

2024-02-05 00:00
Sean Murphy

Strategic Overview

Status
Patched in 1.0.117
Affected ThemeRoyal Elementor Kit
Affected Version<= 1.0.116
CVSS4.3Medium
CVECVE-2024-0835
View all Royal Elementor Kit vulnerabilities

Vulnerability Overview

The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in all versions up to, and including, 1.0.116. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary transients. Note, that these transients can only be updated to true and not arbitrary values.

Technical Analysis

REMEDIATION: Update to version 1.0.117, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C