Executive brief
The Royal Addons for Elementor WordPress plugin contains a flaw that exposes private taxonomy data without requiring authentication. An attacker can query the plugin's endpoint to retrieve names and IDs of taxonomy terms from private/non-public taxonomies that WordPress intentionally hides from public access, potentially exposing sensitive business categorization or internal segmentation of content.
Technical details
The vulnerability is a missing authorization check (broken access control) in the plugin's wpr_get_dependent_terms AJAX action. The endpoint accepts arbitrary taxonomy names and parent term IDs without verifying user capabilities or validating nonce tokens, allowing unauthenticated callers to enumerate taxonomy terms. The root cause is the absence of capability checks (current_user_can) and nonce validation before returning term data from private taxonomies that WordPress core does not expose via REST API or public archives. An attacker can POST to wp-admin/admin-ajax.php with action=wpr_get_dependent_terms, taxonomy=<private_taxonomy>, and parent_term=<guess_or_enumerate> to retrieve all terms assigned to published posts. The vulnerability was fixed in version 1.7.1066.
Affected products
- Royal Addons Royal Addons for Elementor before 1.7.1066
Timeline
- 2026-08-24: disclosed
- 2026-08-26: patched: Fixed in version 1.7.1066