Executive brief
The Royal Addons for Elementor is a popular WordPress plugin that provides additional page-building components and design templates. A vulnerability in versions up to 1.7.1066 allows unauthenticated attackers to extract sensitive metadata from published posts by exploiting a flaw in the search functionality. Since the required security token is publicly exposed on all pages using the plugin, attackers can conduct this attack without needing any special access or authentication.
Technical details
The vulnerability is a sensitive information exposure flaw in the 'wpr_keyword' parameter of the Royal Addons for Elementor plugin. The vulnerable AJAX search module fails to properly validate or restrict access to postmeta queries, allowing attackers to perform character-by-character substring matching across the wp_postmeta table to extract arbitrary metadata values from published posts. No authenticated session is required because the nonce (security token) is emitted publicly via wp_localize_script on any page loading a Royal Elementor widget. Attackers can systematically query the database to reconstruct sensitive metadata field values.
Affected products
- Royal Elementor Addons Royal Addons for Elementor up to 1.7.1066
Timeline
- 2026-09-12: disclosed