plugin

Royal Elementor Addons Vulnerabilities

152 known security issues reported for the Royal Elementor Addons WordPress plugin. Most recent disclosed Aug 21, 2026.

1 critical 11 high 76 medium

Running Royal Elementor Addons on your site? Check whether your installed version is affected.

Scan your site free

Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Authenticated (Administrator+) Remote Code Execution

high

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.7.1066. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with administrator-...

CVSS:
7.2
Affected:
up to 1.7.1066
Fixed in:
1.7.1066
Disclosed:
Aug 21, 2026

CVE-2026-13405 on NVD →

Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (incl...

CVSS:
8.8
Affected:
up to 1.7.1064
Fixed in:
1.7.1065
Disclosed:
Aug 15, 2026

CVE-2026-17123 on NVD →

Royal Elementor Addons <= 1.7.1064 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1064 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.7.1064
Fixed in:
1.7.1065
Disclosed:
Aug 10, 2026

CVE-2026-19217 on NVD →

Royal Elementor Addons <= 1.7.1062 - Unauthenticated Information Exposure

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1062. This makes it possible for unauthenticated attackers to extract mega menu templates.

CVSS:
5.3
Affected:
up to 1.7.1062
Fixed in:
1.7.1063
Disclosed:
Jun 26, 2026

CVE-2026-13402 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable() an...

CVSS:
6.5
Affected:
1.7.1058 – 1.7.1059
Fixed in:
1.7.1060
Disclosed:
Jun 18, 2026

CVE-2026-8118 on NVD →

Royal Addons for Elementor <= 1.7.1058 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...

CVSS:
6.4
Affected:
up to 1.7.1058
Fixed in:
1.7.1059
Disclosed:
May 13, 2026

CVE-2026-6504 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1053 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 1.7.1053
Fixed in:
1.7.1053
Disclosed:
May 7, 2026

CVE-2026-27421 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Missing Authorization

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.7.1053. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.1053
Fixed in:
1.7.1053
Disclosed:
May 7, 2026

CVE-2026-25436 on NVD →

Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter

medium

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
May 4, 2026

CVE-2026-5159 on NVD →

Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce...

CVSS:
7.2
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
May 4, 2026

CVE-2026-4803 on NVD →

Royal Addons for Elementor <= 1.7.1056 - Missing Authorization to Unauthenticated Form Action Meta Modification

medium

The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it acce...

CVSS:
5.3
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
May 1, 2026

CVE-2026-4024 on NVD →

Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter,...

CVSS:
7.2
Affected:
up to 1.7.1057
Fixed in:
1.7.1058
Disclosed:
May 1, 2026

CVE-2026-6229 on NVD →

Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of...

CVSS:
6.4
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
Apr 23, 2026

CVE-2026-5428 on NVD →

Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget

medium

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
Apr 16, 2026

CVE-2026-5162 on NVD →

Royal Elementor Addons < 1.7.1041 - Unauthenticated Stored Cross-Site Scripting

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 1.7.1041
Fixed in:
1.7.1041
Disclosed:
Apr 16, 2026

CVE-2026-40720 on NVD →

Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass

medium

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access an...

CVSS:
6.4
Affected:
up to 1.7.1049
Fixed in:
1.7.1050
Disclosed:
Apr 3, 2026

CVE-2026-0664 on NVD →

Royal Elementor Addons <= 1.7.1056 - Missing Authorization

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1056. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.1056
Fixed in:
1.7.1057
Disclosed:
Mar 31, 2026

CVE-2026-40763 on NVD →

Royal Elementor Addons - WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability

medium

WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability

CVSS:
5.3
Affected:
up to 1.7.1049
Fixed in:
1.7.1050
Disclosed:
Mar 18, 2026

Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthentic...

CVSS:
5.3
Affected:
up to 1.7.1049
Fixed in:
1.7.1050
Disclosed:
Mar 16, 2026

CVE-2026-2373 on NVD →

Royal Elementor Addons - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass vulnerability

high

Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass vulnerability

CVSS:
8.8
Affected:
up to 1.7.1049
Fixed in:
1.7.1050
Disclosed:
Mar 11, 2026

Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass

high

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated at...

CVSS:
8.8
Affected:
up to 1.7.1049
Fixed in:
1.7.1050
Disclosed:
Mar 10, 2026

CVE-2025-13067 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 - Missing Authorization

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1052. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.1052
Fixed in:
1.7.1053
Disclosed:
Feb 26, 2026

CVE-2026-28135 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1037

unknown

[en] The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

Affected:
up to 1.7.1037
Fixed in:
1.7.1037
Disclosed:
Dec 15, 2025

CVE-2025-11363 on NVD →

Royal Elementor Addons and Templates <= 1.7.1036 - Missing Authorization to Unauthenticated Media File Upload

medium

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized media file uploads due to a missing capability check on the 'wpr_addons_upload_file' AJAX endpoint in all versions up to, and including, 1.7.1036. This makes it possible for unauthenticated attacke...

CVSS:
5.3
Affected:
up to 1.7.1036
Fixed in:
1.7.1037
Disclosed:
Nov 24, 2025

CVE-2025-11363 on NVD →

Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library

medium

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contrib...

CVSS:
6.4
Affected:
up to 1.7.1031
Fixed in:
1.7.1032
Disclosed:
Nov 19, 2025

CVE-2025-5092 on NVD →

Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...

CVSS:
6.4
Affected:
up to 1.7.1036
Fixed in:
1.7.1037
Disclosed:
Nov 18, 2025

CVE-2025-6251 on NVD →

Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-le...

CVSS:
6.4
Affected:
up to 1.7.1028
Fixed in:
1.7.1029
Disclosed:
Jun 25, 2025

CVE-2025-5338 on NVD →

Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...

CVSS:
6.4
Affected:
up to 1.7.1020
Fixed in:
1.7.1021
Disclosed:
May 30, 2025

CVE-2025-3813 on NVD →

Royal Elementor Addons <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.7.1017
Fixed in:
1.7.1018
Disclosed:
May 7, 2025

CVE-2025-39361 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1018

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 1.7.1018
Fixed in:
1.7.1018
Disclosed:
May 7, 2025

CVE-2024-12120 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1018

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.

Affected:
up to 1.7.1018
Fixed in:
1.7.1018
Disclosed:
May 7, 2025

CVE-2025-39361 on NVD →

Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
5.4
Affected:
up to 1.7.1017
Fixed in:
1.7.1018
Disclosed:
May 6, 2025

CVE-2024-12120 on NVD →

Royal Elementor Addons <= 1.3.977 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.977 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.3.977
Fixed in:
1.3.979
Disclosed:
Apr 16, 2025

CVE-2025-39543 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.979

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a through 1.3.977.

Affected:
up to 1.3.979
Fixed in:
1.3.979
Disclosed:
Apr 16, 2025

CVE-2025-39543 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1007

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006.

Affected:
up to 1.7.1007
Fixed in:
1.7.1007
Disclosed:
Apr 15, 2025

CVE-2025-26990 on NVD →

Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

CVSS:
6.4
Affected:
up to 1.7.1012
Fixed in:
1.7.1013
Disclosed:
Apr 11, 2025

CVE-2025-1455 on NVD →

Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 1.7.1012
Fixed in:
1.7.1013
Disclosed:
Apr 11, 2025

CVE-2025-1456 on NVD →

Royal Elementor Addons <= 1.7.1006 - Authenticated (Admin+) Server Side Request Forgery

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.1006. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web a...

CVSS:
5.5
Affected:
up to 1.7.1006
Fixed in:
1.7.1007
Disclosed:
Apr 11, 2025

CVE-2025-26990 on NVD →

Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicio...

CVSS:
6.1
Affected:
up to 1.7.1007
Fixed in:
1.7.1008
Disclosed:
Feb 18, 2025

CVE-2025-1441 on NVD →

Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious...

CVSS:
6.1
Affected:
up to 1.7.1006
Fixed in:
1.7.1007
Disclosed:
Jan 13, 2025

CVE-2025-0393 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.987.

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Dec 31, 2024

CVE-2024-56062 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Reflected XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.

Affected:
up to 1.7.1002
Fixed in:
1.7.1002
Disclosed:
Dec 31, 2024

CVE-2024-56226 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002

unknown

[en] Missing Authorization vulnerability in WP Royal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.

Affected:
up to 1.7.1002
Fixed in:
1.7.1002
Disclosed:
Dec 31, 2024

CVE-2024-56227 on NVD →

Royal Elementor Addons <= 1.7.1001 - Reflected Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 1.7.1001
Fixed in:
1.7.1002
Disclosed:
Dec 19, 2024

CVE-2024-56226 on NVD →

Royal Elementor Addons <= 1.7.1001 - Missing Authorization

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1001. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized actio...

CVSS:
4.3
Affected:
up to 1.7.1001
Fixed in:
1.7.1002
Disclosed:
Dec 19, 2024

CVE-2024-56227 on NVD →

Royal Elementor Addons <= 1.3.987 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.987 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.3.987
Fixed in:
1.7.1
Disclosed:
Dec 18, 2024

CVE-2024-56062 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1004

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-l...

Affected:
up to 1.7.1004
Fixed in:
1.7.1004
Disclosed:
Nov 28, 2024

CVE-2024-10798 on NVD →

Royal Elementor Addons and Templates <= 1.7.1003 - Authenticated (Contributor+) Post Disclosure

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level...

CVSS:
4.3
Affected:
up to 1.7.1003
Fixed in:
1.7.1004
Disclosed:
Nov 27, 2024

CVE-2024-10798 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

Affected:
up to 1.7.1002
Fixed in:
1.7.1002
Disclosed:
Nov 13, 2024

CVE-2024-9668 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...

Affected:
up to 1.7.1002
Fixed in:
1.7.1002
Disclosed:
Nov 13, 2024

CVE-2024-9682 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...

Affected:
up to 1.7.1002
Fixed in:
1.7.1002
Disclosed:
Nov 13, 2024

CVE-2024-9059 on NVD →

Royal Elementor Addons and Template <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce...

CVSS:
6.4
Affected:
up to 1.7.1001
Fixed in:
1.7.1002
Disclosed:
Nov 12, 2024

CVE-2024-9059 on NVD →

Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 1.7.1001
Fixed in:
1.7.1002
Disclosed:
Nov 12, 2024

CVE-2024-9668 on NVD →

Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 1.7.1001
Fixed in:
1.7.1002
Disclosed:
Nov 12, 2024

CVE-2024-9682 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.981

unknown

[en] Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through 1.3.980.

Affected:
up to 1.3.981
Fixed in:
1.3.981
Disclosed:
Oct 28, 2024

CVE-2024-50442 on NVD →

Royal Elementor Addons <= 1.3.980 - Authenticated (Author+) External Entity Injection

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions up to, and including, 1.3.980. This is due to improper restriction and sanitization on external entities. This makes it possible for authenticated attackers, with author-level access and above, to in...

CVSS:
5.4
Affected:
up to 1.3.980
Fixed in:
1.3.981
Disclosed:
Oct 24, 2024

CVE-2024-50442 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.

Affected:
up to 1.3.987
Fixed in:
1.3.987
Disclosed:
Oct 17, 2024

CVE-2024-7417 on NVD →

Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosure

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.

CVSS:
4.3
Affected:
up to 1.3.986
Fixed in:
1.3.987
Disclosed:
Oct 16, 2024

CVE-2024-7417 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.33

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.3.33
Fixed in:
1.3.33
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acc...

Affected:
up to 1.3.987
Fixed in:
1.3.987
Disclosed:
Oct 8, 2024

CVE-2024-8482 on NVD →

Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a...

CVSS:
6.4
Affected:
up to 1.3.986
Fixed in:
1.3.987
Disclosed:
Oct 7, 2024

CVE-2024-8482 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.985

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.982.

Affected:
up to 1.3.985
Fixed in:
1.3.985
Disclosed:
Sep 17, 2024

CVE-2024-44001 on NVD →

Royal Elementor Addons <= 1.3.982 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.3.982
Fixed in:
1.3.985
Disclosed:
Aug 29, 2024

CVE-2024-44001 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.981

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...

Affected:
up to 1.3.981
Fixed in:
1.3.981
Disclosed:
Jul 24, 2024

CVE-2024-5818 on NVD →

Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

CVSS:
6.4
Affected:
up to 1.3.980
Fixed in:
1.3.981
Disclosed:
Jul 23, 2024

CVE-2024-5818 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.977

unknown

[en] The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permis...

Affected:
up to 1.3.977
Fixed in:
1.3.977
Disclosed:
Jun 7, 2024

CVE-2024-4488 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.977

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...

Affected:
up to 1.3.977
Fixed in:
1.3.977
Disclosed:
Jun 7, 2024

CVE-2024-4489 on NVD →

Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.4
Affected:
up to 1.3.976
Fixed in:
1.3.977
Disclosed:
Jun 6, 2024

CVE-2024-4489 on NVD →

Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions...

CVSS:
6.4
Affected:
up to 1.3.976
Fixed in:
1.3.977
Disclosed:
Jun 6, 2024

CVE-2024-4488 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.976

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. T...

Affected:
up to 1.3.976
Fixed in:
1.3.976
Disclosed:
Jun 1, 2024

CVE-2024-4342 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.976

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...

Affected:
up to 1.3.976
Fixed in:
1.3.976
Disclosed:
Jun 1, 2024

CVE-2024-4087 on NVD →

Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 1.3.975
Fixed in:
1.3.976
Disclosed:
May 31, 2024

CVE-2024-4087 on NVD →

Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This m...

CVSS:
6.4
Affected:
up to 1.3.975
Fixed in:
1.3.976
Disclosed:
May 31, 2024

CVE-2024-4342 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95

unknown

[en] Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.

Affected:
up to 1.3.95
Fixed in:
1.3.95
Disclosed:
May 17, 2024

CVE-2024-32786 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.975

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

Affected:
up to 1.3.975
Fixed in:
1.3.975
Disclosed:
May 16, 2024

CVE-2024-3887 on NVD →

Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

CVSS:
5.4
Affected:
up to 1.3.974
Fixed in:
1.3.975
Disclosed:
May 15, 2024

CVE-2024-3887 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on...

Affected:
up to 1.3.95
Fixed in:
1.3.95
Disclosed:
May 2, 2024

CVE-2024-1567 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attribu...

Affected:
up to 1.3.972
Fixed in:
1.3.972
Disclosed:
May 2, 2024

CVE-2024-3675 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This...

Affected:
up to 1.3.972
Fixed in:
1.3.972
Disclosed:
Apr 23, 2024

CVE-2024-3889 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...

Affected:
up to 1.3.972
Fixed in:
1.3.972
Disclosed:
Apr 23, 2024

CVE-2024-2799 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

Affected:
up to 1.3.972
Fixed in:
1.3.972
Disclosed:
Apr 23, 2024

CVE-2024-2798 on NVD →

Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes....

CVSS:
6.4
Affected:
up to 1.3.971
Fixed in:
1.3.972
Disclosed:
Apr 22, 2024

CVE-2024-3675 on NVD →

Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

CVSS:
6.4
Affected:
up to 1.3.971
Fixed in:
1.3.972
Disclosed:
Apr 22, 2024

CVE-2024-2799 on NVD →

Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 1.3.971
Fixed in:
1.3.972
Disclosed:
Apr 22, 2024

CVE-2024-2798 on NVD →

Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This make...

CVSS:
6.4
Affected:
up to 1.3.971
Fixed in:
1.3.972
Disclosed:
Apr 22, 2024

CVE-2024-3889 on NVD →

Royal Elementor Addons <= 1.3.93 - Unauthenticated IP Spoofing

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.3.93 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP adress.

CVSS:
5.3
Affected:
up to 1.3.93
Fixed in:
1.3.95
Disclosed:
Apr 22, 2024

CVE-2024-32786 on NVD →

Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload

high

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the a...

CVSS:
8.2
Affected:
up to 1.3.94
Fixed in:
1.3.95
Disclosed:
Apr 19, 2024

CVE-2024-1567 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.93.

Affected:
up to 1.3.95
Fixed in:
1.3.95
Disclosed:
Apr 7, 2024

CVE-2024-31236 on NVD →

Royal Elementor Addons <= 1.3.93 - Authenticated (Contributor+) Stored Cross-Site Scriting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acces...

CVSS:
6.4
Affected:
up to 1.3.93
Fixed in:
1.3.95
Disclosed:
Apr 5, 2024

CVE-2024-31236 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.92

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contr...

Affected:
up to 1.3.92
Fixed in:
1.3.92
Disclosed:
Mar 7, 2024

CVE-2024-1500 on NVD →

Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributo...

CVSS:
5.4
Affected:
up to 1.3.91
Fixed in:
1.3.92
Disclosed:
Mar 6, 2024

CVE-2024-1500 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access o...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0442 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wis...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0512 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadat...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0516 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user comp...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0514 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items fro...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0513 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 20, 2024

CVE-2024-0515 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or hig...

CVSS:
6.4
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 8, 2024

CVE-2024-0442 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88

unknown

[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post meta...

Affected:
up to 1.3.88
Fixed in:
1.3.88
Disclosed:
Feb 8, 2024

CVE-2024-0511 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.

CVSS:
5.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0516 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from use...

CVSS:
4.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0513 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user...

CVSS:
4.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0515 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare l...

CVSS:
4.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0514 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlist...

CVSS:
4.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0512 on NVD →

Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata...

CVSS:
4.3
Affected:
up to 1.3.87
Fixed in:
1.3.88
Disclosed:
Feb 7, 2024

CVE-2024-0511 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.81

unknown

[en] The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages c...

Affected:
up to 1.3.81
Fixed in:
1.3.81
Disclosed:
Jan 16, 2024

CVE-2023-5922 on NVD →

Royal Elementor Addons and Templates <= 1.3.80 - Missing Authorization to Private/Password Protected Post Read

medium

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpr_get_page_content AJAX action in all versions up to, and including, 1.3.80. This makes it possible for unauthenticated attackers to view password protected posts and pag...

CVSS:
5.3
Affected:
up to 1.3.80
Fixed in:
1.3.81
Disclosed:
Dec 6, 2023

CVE-2023-5922 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79

unknown

[en] The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Affected:
up to 1.3.79
Fixed in:
1.3.79
Disclosed:
Oct 31, 2023

CVE-2023-5360 on NVD →

Royal Elementor Addons and Templates <= 1.3.78 - Unauthenticated Arbitrary File Upload

critical

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.3.78. This is due to insufficient file type validation in the handle_file_upload() function called via AJAX which allows attackers to supply a preferred filetype extension to the...

CVSS:
9.8
Affected:
up to 1.3.78
Fixed in:
1.3.79
Disclosed:
Oct 9, 2023

CVE-2023-5360 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] <= 1.3.75

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.

Affected:
up to 1.3.75
Fixed in:
1.3.75
Disclosed:
Oct 6, 2023

CVE-2022-47175 on NVD →

Royal Elementor Addons <= 1.3.75 - Cross-Site Request Forgery

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.75. This is due to missing or incorrect nonce validation on several functions including wpr_rating_dismiss_notice, wpr_rating_already_rated, wpr_pro_features_dismiss_notice. This makes it po...

CVSS:
4.3
Affected:
up to 1.3.75
Fixed in:
1.3.76
Disclosed:
Aug 22, 2023

CVE-2022-47175 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
1.3 – 1.3.70
Fixed in:
1.3.71
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailC...

Affected:
up to 1.3.71
Fixed in:
1.3.71
Disclosed:
Jul 18, 2023

CVE-2023-3709 on NVD →

Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp...

CVSS:
5.3
Affected:
up to 1.3.70
Fixed in:
1.3.71
Disclosed:
Jul 17, 2023

CVE-2023-3709 on NVD →

Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthentica...

CVSS:
6.1
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4710 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates includ...

CVSS:
5.4
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4704 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it...

CVSS:
5.4
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4702 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If n...

CVSS:
5.4
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4700 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4705 on NVD →

Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can trick...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4707 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-librar...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4701 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4703 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates a...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4708 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any m...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4711 on NVD →

Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin'...

CVSS:
4.3
Affected:
up to 1.3.59
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4709 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthe...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4710 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates i...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4704 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4703 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the pl...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4709 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can t...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4707 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templa...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4708 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configura...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4705 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unles...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4702 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-l...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4701 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for...

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4711 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60

unknown

[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme....

Affected:
up to 1.3.60
Fixed in:
1.3.60
Disclosed:
Jan 10, 2023

CVE-2022-4700 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56

unknown

[en] The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.

Affected:
up to 1.3.56
Fixed in:
1.3.56
Disclosed:
Jan 9, 2023

CVE-2022-4102 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56

unknown

[en] The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title

Affected:
up to 1.3.56
Fixed in:
1.3.56
Disclosed:
Jan 9, 2023

CVE-2022-4103 on NVD →

Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on the wpr_delete_template and wpr_create_template functions. This makes it possible for unauthenticated attackers to delete or creat...

CVSS:
8.1
Affected:
up to 1.3.55
Fixed in:
1.3.56
Disclosed:
Dec 15, 2022

CVE-2022-4102 on NVD →

Royal Elementor Addons <=1.3.55 - Authenticated (Subscriber+) Arbitrary Post Deletion

high

The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template deletion in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify whether the deleted post is a template. This makes it pos...

CVSS:
8.1
Affected:
up to 1.3.55
Fixed in:
1.3.56
Disclosed:
Dec 15, 2022

CVE-2022-4102 on NVD →

Royal Elementor Addons <=1.3.55 - Missing Authorization to Subscriber+ Arbitrary Post Creation

medium

The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template creation in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify whether the created post is a template. This makes it pos...

CVSS:
6.5
Affected:
up to 1.3.55
Fixed in:
1.3.56
Disclosed:
Dec 15, 2022

CVE-2022-4103 on NVD →

Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery

high

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via forged request granted they...

CVSS:
8.8
Affected:
up to 1.3.55
Fixed in:
1.3.56
Disclosed:
Dec 6, 2022

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56

unknown

The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via forged request granted they...

Affected:
up to 1.3.56
Fixed in:
1.3.56
Disclosed:
Dec 6, 2022

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.3.33
Fixed in:
1.3.33
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.33

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.3.33
Fixed in:
1.3.33
Disclosed:
Mar 4, 2022

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.3.71
Fixed in:
1.3.71

CVE-2023-33999 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1007

unknown
Affected:
up to 1.7.1007
Fixed in:
1.7.1007

CVE-2025-0393 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1008

unknown
Affected:
up to 1.7.1008
Fixed in:
1.7.1008

CVE-2025-1441 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1013

unknown
Affected:
up to 1.7.1013
Fixed in:
1.7.1013

CVE-2025-1455 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1013

unknown
Affected:
up to 1.7.1013
Fixed in:
1.7.1013

CVE-2025-1456 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1021

unknown
Affected:
up to 1.7.1021
Fixed in:
1.7.1021

CVE-2025-3813 on NVD →

Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1025

unknown
Affected:
up to 1.7.1025
Fixed in:
1.7.1025

CVE-2025-5338 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database