The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.
| Software | From | Fixed in |
|---|---|---|
| royal-elementor-addons / royal_elementor_addons | - | 1.3.88 |