Executive brief
Royal Elementor Addons is a WordPress plugin that adds interactive features like post likes and visitor tracking to content pages. The plugin contains an authorization bypass flaw that allows attackers to fraudulently modify like counts and visitor tracking data on any post, including private and draft posts, without authentication. This can enable content manipulation, false engagement metrics, and information exposure.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the wpr_likes_init AJAX action. The plugin fails to validate user capabilities or post ownership before writing post metadata (_post_like_count, _post_like_modified, _user_IP), relying only on a publicly-scrapeable WordPress nonce. Since WordPress issues a shared nonce (user-0) to anonymous visitors, an attacker can scrape this nonce from any public page rendering a Post Likes element, then replay it anonymously against any post ID, including those the attacker has no access to. The attacker can then increment like counts and inject arbitrary IP addresses via the Client-IP header. No authentication is required; the attack is purely network-based and exploits broken access control on the AJAX endpoint.
Affected products
- Royal Elementor Royal Addons for Elementor before 1.7.1066
Timeline
- 2026-08-24: disclosed: Publicly published vulnerability
- 2026-08-26: patched: Fixed in version 1.7.1066