Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52014 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation | |
| Weaknesses | CWE-284 | |
| References |
|
Mon, 13 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:23:26.369Z
Reserved: 2022-12-23T16:57:00.810Z
Link: CVE-2022-4702
Updated: 2024-08-03T01:48:40.415Z
Status : Modified
Published: 2023-01-10T17:15:11.290
Modified: 2026-04-08T19:17:57.403
Link: CVE-2022-4702
No data.
OpenCVE Enrichment
No data.
EUVD