First published: Mon Feb 05 2024(Updated: )
The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in all versions up to, and including, 1.0.116. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary transients. Note, that these transients can only be updated to true and not arbitrary values.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Royal Elementor Addons | <=1.0.116 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0835 is considered a medium severity vulnerability as it allows authenticated attackers to perform unauthorized actions.
To fix CVE-2024-0835, you should update the Royal Elementor Kit theme to version 1.0.117 or later.
CVE-2024-0835 affects users of the Royal Elementor Kit theme for WordPress in versions up to and including 1.0.116.
CVE-2024-0835 enables authenticated attackers with subscriber access or higher to perform unauthorized arbitrary transient updates.
There is no known workaround for CVE-2024-0835, so upgrading to the latest version is the recommended solution.