CyberRota Analysis
AI-GeneratedThe Royal Addons for Elementor WordPress plugin prior to version 1.7.1063 is vulnerable due to inadequate checks on the post status of menu items and their referenced templates in a REST endpoint. This flaw allows unauthenticated users to access and retrieve rendered HTML content from private or draft Elementor templates linked to non-public navigation menus. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exposure of sensitive content.
Original NVD Description
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.