CVE-2025-1441: Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wprfilterwooproducts' function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1441?
CVE-2025-1441 has a medium severity level due to its potential for unauthorized actions through Cross-Site Request Forgery.
How do I fix CVE-2025-1441?
To fix CVE-2025-1441, update the Royal Elementor Addons and Templates plugin to version 1.7.1008 or later.
What versions are affected by CVE-2025-1441?
CVE-2025-1441 affects all versions of the Royal Elementor Addons and Templates plugin up to and including 1.7.1007.
What is Cross-Site Request Forgery in the context of CVE-2025-1441?
Cross-Site Request Forgery in CVE-2025-1441 refers to the vulnerability that allows attackers to perform actions on behalf of authenticated users without their consent.
Is there a specific function that is vulnerable in CVE-2025-1441?
Yes, the vulnerability in CVE-2025-1441 is specifically related to the 'wpr_filter_woo_products' function due to missing or incorrect nonce validation.