Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Authenticated (Administrator+) Remote Code Execution
high
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.7.1066. This is due to insufficient validation of user supplied input before it is executed. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 7.2
- Affected:
- up to 1.7.1066
- Fixed in:
- 1.7.1066
- Disclosed:
- Aug 21, 2026
CVE-2026-13405 on NVD →
Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (incl...
- CVSS:
- 8.8
- Affected:
- up to 1.7.1064
- Fixed in:
- 1.7.1065
- Disclosed:
- Aug 15, 2026
CVE-2026-17123 on NVD →
Royal Elementor Addons <= 1.7.1064 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1064 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1064
- Fixed in:
- 1.7.1065
- Disclosed:
- Aug 10, 2026
CVE-2026-19217 on NVD →
Royal Elementor Addons <= 1.7.1062 - Unauthenticated Information Exposure
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1062. This makes it possible for unauthenticated attackers to extract mega menu templates.
- CVSS:
- 5.3
- Affected:
- up to 1.7.1062
- Fixed in:
- 1.7.1063
- Disclosed:
- Jun 26, 2026
CVE-2026-13402 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable() an...
- CVSS:
- 6.5
- Affected:
- 1.7.1058 – 1.7.1059
- Fixed in:
- 1.7.1060
- Disclosed:
- Jun 18, 2026
CVE-2026-8118 on NVD →
Royal Addons for Elementor <= 1.7.1058 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1058
- Fixed in:
- 1.7.1059
- Disclosed:
- May 13, 2026
CVE-2026-6504 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1053 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1053
- Fixed in:
- 1.7.1053
- Disclosed:
- May 7, 2026
CVE-2026-27421 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Missing Authorization
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.7.1053. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.1053
- Fixed in:
- 1.7.1053
- Disclosed:
- May 7, 2026
CVE-2026-25436 on NVD →
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter
medium
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- May 4, 2026
CVE-2026-5159 on NVD →
Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce...
- CVSS:
- 7.2
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- May 4, 2026
CVE-2026-4803 on NVD →
Royal Addons for Elementor <= 1.7.1056 - Missing Authorization to Unauthenticated Form Action Meta Modification
medium
The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it acce...
- CVSS:
- 5.3
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- May 1, 2026
CVE-2026-4024 on NVD →
Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter,...
- CVSS:
- 7.2
- Affected:
- up to 1.7.1057
- Fixed in:
- 1.7.1058
- Disclosed:
- May 1, 2026
CVE-2026-6229 on NVD →
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- Apr 23, 2026
CVE-2026-5428 on NVD →
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget
medium
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- Apr 16, 2026
CVE-2026-5162 on NVD →
Royal Elementor Addons < 1.7.1041 - Unauthenticated Stored Cross-Site Scripting
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 1.7.1041
- Fixed in:
- 1.7.1041
- Disclosed:
- Apr 16, 2026
CVE-2026-40720 on NVD →
Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass
medium
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access an...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1049
- Fixed in:
- 1.7.1050
- Disclosed:
- Apr 3, 2026
CVE-2026-0664 on NVD →
Royal Elementor Addons <= 1.7.1056 - Missing Authorization
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1056. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.1056
- Fixed in:
- 1.7.1057
- Disclosed:
- Mar 31, 2026
CVE-2026-40763 on NVD →
Royal Elementor Addons - WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
medium
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
- CVSS:
- 5.3
- Affected:
- up to 1.7.1049
- Fixed in:
- 1.7.1050
- Disclosed:
- Mar 18, 2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthentic...
- CVSS:
- 5.3
- Affected:
- up to 1.7.1049
- Fixed in:
- 1.7.1050
- Disclosed:
- Mar 16, 2026
CVE-2026-2373 on NVD →
Royal Elementor Addons - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass vulnerability
high
Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass vulnerability
- CVSS:
- 8.8
- Affected:
- up to 1.7.1049
- Fixed in:
- 1.7.1050
- Disclosed:
- Mar 11, 2026
Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass
high
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated at...
- CVSS:
- 8.8
- Affected:
- up to 1.7.1049
- Fixed in:
- 1.7.1050
- Disclosed:
- Mar 10, 2026
CVE-2025-13067 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 - Missing Authorization
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1052. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.7.1052
- Fixed in:
- 1.7.1053
- Disclosed:
- Feb 26, 2026
CVE-2026-28135 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1037
unknown
[en] The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.
- Affected:
- up to 1.7.1037
- Fixed in:
- 1.7.1037
- Disclosed:
- Dec 15, 2025
CVE-2025-11363 on NVD →
Royal Elementor Addons and Templates <= 1.7.1036 - Missing Authorization to Unauthenticated Media File Upload
medium
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized media file uploads due to a missing capability check on the 'wpr_addons_upload_file' AJAX endpoint in all versions up to, and including, 1.7.1036. This makes it possible for unauthenticated attacke...
- CVSS:
- 5.3
- Affected:
- up to 1.7.1036
- Fixed in:
- 1.7.1037
- Disclosed:
- Nov 24, 2025
CVE-2025-11363 on NVD →
Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
medium
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contrib...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1031
- Fixed in:
- 1.7.1032
- Disclosed:
- Nov 19, 2025
CVE-2025-5092 on NVD →
Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1036
- Fixed in:
- 1.7.1037
- Disclosed:
- Nov 18, 2025
CVE-2025-6251 on NVD →
Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1028
- Fixed in:
- 1.7.1029
- Disclosed:
- Jun 25, 2025
CVE-2025-5338 on NVD →
Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1020
- Fixed in:
- 1.7.1021
- Disclosed:
- May 30, 2025
CVE-2025-3813 on NVD →
Royal Elementor Addons <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1017
- Fixed in:
- 1.7.1018
- Disclosed:
- May 7, 2025
CVE-2025-39361 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1018
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 1.7.1018
- Fixed in:
- 1.7.1018
- Disclosed:
- May 7, 2025
CVE-2024-12120 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1018
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.
- Affected:
- up to 1.7.1018
- Fixed in:
- 1.7.1018
- Disclosed:
- May 7, 2025
CVE-2025-39361 on NVD →
Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 5.4
- Affected:
- up to 1.7.1017
- Fixed in:
- 1.7.1018
- Disclosed:
- May 6, 2025
CVE-2024-12120 on NVD →
Royal Elementor Addons <= 1.3.977 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.977 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.3.977
- Fixed in:
- 1.3.979
- Disclosed:
- Apr 16, 2025
CVE-2025-39543 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.979
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a through 1.3.977.
- Affected:
- up to 1.3.979
- Fixed in:
- 1.3.979
- Disclosed:
- Apr 16, 2025
CVE-2025-39543 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1007
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006.
- Affected:
- up to 1.7.1007
- Fixed in:
- 1.7.1007
- Disclosed:
- Apr 15, 2025
CVE-2025-26990 on NVD →
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1012
- Fixed in:
- 1.7.1013
- Disclosed:
- Apr 11, 2025
CVE-2025-1455 on NVD →
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1012
- Fixed in:
- 1.7.1013
- Disclosed:
- Apr 11, 2025
CVE-2025-1456 on NVD →
Royal Elementor Addons <= 1.7.1006 - Authenticated (Admin+) Server Side Request Forgery
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.1006. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web a...
- CVSS:
- 5.5
- Affected:
- up to 1.7.1006
- Fixed in:
- 1.7.1007
- Disclosed:
- Apr 11, 2025
CVE-2025-26990 on NVD →
Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicio...
- CVSS:
- 6.1
- Affected:
- up to 1.7.1007
- Fixed in:
- 1.7.1008
- Disclosed:
- Feb 18, 2025
CVE-2025-1441 on NVD →
Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious...
- CVSS:
- 6.1
- Affected:
- up to 1.7.1006
- Fixed in:
- 1.7.1007
- Disclosed:
- Jan 13, 2025
CVE-2025-0393 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.987.
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Dec 31, 2024
CVE-2024-56062 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Reflected XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.
- Affected:
- up to 1.7.1002
- Fixed in:
- 1.7.1002
- Disclosed:
- Dec 31, 2024
CVE-2024-56226 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002
unknown
[en] Missing Authorization vulnerability in WP Royal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.
- Affected:
- up to 1.7.1002
- Fixed in:
- 1.7.1002
- Disclosed:
- Dec 31, 2024
CVE-2024-56227 on NVD →
Royal Elementor Addons <= 1.7.1001 - Reflected Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- CVSS:
- 6.1
- Affected:
- up to 1.7.1001
- Fixed in:
- 1.7.1002
- Disclosed:
- Dec 19, 2024
CVE-2024-56226 on NVD →
Royal Elementor Addons <= 1.7.1001 - Missing Authorization
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1001. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized actio...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1001
- Fixed in:
- 1.7.1002
- Disclosed:
- Dec 19, 2024
CVE-2024-56227 on NVD →
Royal Elementor Addons <= 1.3.987 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.987 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.3.987
- Fixed in:
- 1.7.1
- Disclosed:
- Dec 18, 2024
CVE-2024-56062 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1004
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-l...
- Affected:
- up to 1.7.1004
- Fixed in:
- 1.7.1004
- Disclosed:
- Nov 28, 2024
CVE-2024-10798 on NVD →
Royal Elementor Addons and Templates <= 1.7.1003 - Authenticated (Contributor+) Post Disclosure
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 1.7.1003
- Fixed in:
- 1.7.1004
- Disclosed:
- Nov 27, 2024
CVE-2024-10798 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- Affected:
- up to 1.7.1002
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 13, 2024
CVE-2024-9668 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- Affected:
- up to 1.7.1002
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 13, 2024
CVE-2024-9682 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1002
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level...
- Affected:
- up to 1.7.1002
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 13, 2024
CVE-2024-9059 on NVD →
Royal Elementor Addons and Template <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1001
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 12, 2024
CVE-2024-9059 on NVD →
Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1001
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 12, 2024
CVE-2024-9668 on NVD →
Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 1.7.1001
- Fixed in:
- 1.7.1002
- Disclosed:
- Nov 12, 2024
CVE-2024-9682 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.981
unknown
[en] Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through 1.3.980.
- Affected:
- up to 1.3.981
- Fixed in:
- 1.3.981
- Disclosed:
- Oct 28, 2024
CVE-2024-50442 on NVD →
Royal Elementor Addons <= 1.3.980 - Authenticated (Author+) External Entity Injection
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions up to, and including, 1.3.980. This is due to improper restriction and sanitization on external entities. This makes it possible for authenticated attackers, with author-level access and above, to in...
- CVSS:
- 5.4
- Affected:
- up to 1.3.980
- Fixed in:
- 1.3.981
- Disclosed:
- Oct 24, 2024
CVE-2024-50442 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.
- Affected:
- up to 1.3.987
- Fixed in:
- 1.3.987
- Disclosed:
- Oct 17, 2024
CVE-2024-7417 on NVD →
Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosure
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.
- CVSS:
- 4.3
- Affected:
- up to 1.3.986
- Fixed in:
- 1.3.987
- Disclosed:
- Oct 16, 2024
CVE-2024-7417 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.33
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.3.33
- Fixed in:
- 1.3.33
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.987
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acc...
- Affected:
- up to 1.3.987
- Fixed in:
- 1.3.987
- Disclosed:
- Oct 8, 2024
CVE-2024-8482 on NVD →
Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a...
- CVSS:
- 6.4
- Affected:
- up to 1.3.986
- Fixed in:
- 1.3.987
- Disclosed:
- Oct 7, 2024
CVE-2024-8482 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.985
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.982.
- Affected:
- up to 1.3.985
- Fixed in:
- 1.3.985
- Disclosed:
- Sep 17, 2024
CVE-2024-44001 on NVD →
Royal Elementor Addons <= 1.3.982 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 1.3.982
- Fixed in:
- 1.3.985
- Disclosed:
- Aug 29, 2024
CVE-2024-44001 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.981
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...
- Affected:
- up to 1.3.981
- Fixed in:
- 1.3.981
- Disclosed:
- Jul 24, 2024
CVE-2024-5818 on NVD →
Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...
- CVSS:
- 6.4
- Affected:
- up to 1.3.980
- Fixed in:
- 1.3.981
- Disclosed:
- Jul 23, 2024
CVE-2024-5818 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.977
unknown
[en] The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permis...
- Affected:
- up to 1.3.977
- Fixed in:
- 1.3.977
- Disclosed:
- Jun 7, 2024
CVE-2024-4488 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.977
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributo...
- Affected:
- up to 1.3.977
- Fixed in:
- 1.3.977
- Disclosed:
- Jun 7, 2024
CVE-2024-4489 on NVD →
Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 1.3.976
- Fixed in:
- 1.3.977
- Disclosed:
- Jun 6, 2024
CVE-2024-4489 on NVD →
Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions...
- CVSS:
- 6.4
- Affected:
- up to 1.3.976
- Fixed in:
- 1.3.977
- Disclosed:
- Jun 6, 2024
CVE-2024-4488 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.976
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. T...
- Affected:
- up to 1.3.976
- Fixed in:
- 1.3.976
- Disclosed:
- Jun 1, 2024
CVE-2024-4342 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.976
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...
- Affected:
- up to 1.3.976
- Fixed in:
- 1.3.976
- Disclosed:
- Jun 1, 2024
CVE-2024-4087 on NVD →
Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 1.3.975
- Fixed in:
- 1.3.976
- Disclosed:
- May 31, 2024
CVE-2024-4087 on NVD →
Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This m...
- CVSS:
- 6.4
- Affected:
- up to 1.3.975
- Fixed in:
- 1.3.976
- Disclosed:
- May 31, 2024
CVE-2024-4342 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95
unknown
[en] Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.
- Affected:
- up to 1.3.95
- Fixed in:
- 1.3.95
- Disclosed:
- May 17, 2024
CVE-2024-32786 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.975
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- Affected:
- up to 1.3.975
- Fixed in:
- 1.3.975
- Disclosed:
- May 16, 2024
CVE-2024-3887 on NVD →
Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- CVSS:
- 5.4
- Affected:
- up to 1.3.974
- Fixed in:
- 1.3.975
- Disclosed:
- May 15, 2024
CVE-2024-3887 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on...
- Affected:
- up to 1.3.95
- Fixed in:
- 1.3.95
- Disclosed:
- May 2, 2024
CVE-2024-1567 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attribu...
- Affected:
- up to 1.3.972
- Fixed in:
- 1.3.972
- Disclosed:
- May 2, 2024
CVE-2024-3675 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This...
- Affected:
- up to 1.3.972
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 23, 2024
CVE-2024-3889 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible...
- Affected:
- up to 1.3.972
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 23, 2024
CVE-2024-2799 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.972
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- Affected:
- up to 1.3.972
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 23, 2024
CVE-2024-2798 on NVD →
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes....
- CVSS:
- 6.4
- Affected:
- up to 1.3.971
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 22, 2024
CVE-2024-3675 on NVD →
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...
- CVSS:
- 6.4
- Affected:
- up to 1.3.971
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 22, 2024
CVE-2024-2799 on NVD →
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 1.3.971
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 22, 2024
CVE-2024-2798 on NVD →
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This make...
- CVSS:
- 6.4
- Affected:
- up to 1.3.971
- Fixed in:
- 1.3.972
- Disclosed:
- Apr 22, 2024
CVE-2024-3889 on NVD →
Royal Elementor Addons <= 1.3.93 - Unauthenticated IP Spoofing
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.3.93 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP adress.
- CVSS:
- 5.3
- Affected:
- up to 1.3.93
- Fixed in:
- 1.3.95
- Disclosed:
- Apr 22, 2024
CVE-2024-32786 on NVD →
Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload
high
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the a...
- CVSS:
- 8.2
- Affected:
- up to 1.3.94
- Fixed in:
- 1.3.95
- Disclosed:
- Apr 19, 2024
CVE-2024-1567 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.95
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.3.93.
- Affected:
- up to 1.3.95
- Fixed in:
- 1.3.95
- Disclosed:
- Apr 7, 2024
CVE-2024-31236 on NVD →
Royal Elementor Addons <= 1.3.93 - Authenticated (Contributor+) Stored Cross-Site Scriting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acces...
- CVSS:
- 6.4
- Affected:
- up to 1.3.93
- Fixed in:
- 1.3.95
- Disclosed:
- Apr 5, 2024
CVE-2024-31236 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.92
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contr...
- Affected:
- up to 1.3.92
- Fixed in:
- 1.3.92
- Disclosed:
- Mar 7, 2024
CVE-2024-1500 on NVD →
Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributo...
- CVSS:
- 5.4
- Affected:
- up to 1.3.91
- Fixed in:
- 1.3.92
- Disclosed:
- Mar 6, 2024
CVE-2024-1500 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access o...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0442 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wis...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0512 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadat...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0516 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user comp...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0514 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items fro...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0513 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 20, 2024
CVE-2024-0515 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or hig...
- CVSS:
- 6.4
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 8, 2024
CVE-2024-0442 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.88
unknown
[en] The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post meta...
- Affected:
- up to 1.3.88
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 8, 2024
CVE-2024-0511 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.
- CVSS:
- 5.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0516 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from use...
- CVSS:
- 4.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0513 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user...
- CVSS:
- 4.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0515 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare l...
- CVSS:
- 4.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0514 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlist...
- CVSS:
- 4.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0512 on NVD →
Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata...
- CVSS:
- 4.3
- Affected:
- up to 1.3.87
- Fixed in:
- 1.3.88
- Disclosed:
- Feb 7, 2024
CVE-2024-0511 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.81
unknown
[en] The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages c...
- Affected:
- up to 1.3.81
- Fixed in:
- 1.3.81
- Disclosed:
- Jan 16, 2024
CVE-2023-5922 on NVD →
Royal Elementor Addons and Templates <= 1.3.80 - Missing Authorization to Private/Password Protected Post Read
medium
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpr_get_page_content AJAX action in all versions up to, and including, 1.3.80. This makes it possible for unauthenticated attackers to view password protected posts and pag...
- CVSS:
- 5.3
- Affected:
- up to 1.3.80
- Fixed in:
- 1.3.81
- Disclosed:
- Dec 6, 2023
CVE-2023-5922 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79
unknown
[en] The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
- Affected:
- up to 1.3.79
- Fixed in:
- 1.3.79
- Disclosed:
- Oct 31, 2023
CVE-2023-5360 on NVD →
Royal Elementor Addons and Templates <= 1.3.78 - Unauthenticated Arbitrary File Upload
critical
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.3.78. This is due to insufficient file type validation in the handle_file_upload() function called via AJAX which allows attackers to supply a preferred filetype extension to the...
- CVSS:
- 9.8
- Affected:
- up to 1.3.78
- Fixed in:
- 1.3.79
- Disclosed:
- Oct 9, 2023
CVE-2023-5360 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] <= 1.3.75
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.
- Affected:
- up to 1.3.75
- Fixed in:
- 1.3.75
- Disclosed:
- Oct 6, 2023
CVE-2022-47175 on NVD →
Royal Elementor Addons <= 1.3.75 - Cross-Site Request Forgery
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.75. This is due to missing or incorrect nonce validation on several functions including wpr_rating_dismiss_notice, wpr_rating_already_rated, wpr_pro_features_dismiss_notice. This makes it po...
- CVSS:
- 4.3
- Affected:
- up to 1.3.75
- Fixed in:
- 1.3.76
- Disclosed:
- Aug 22, 2023
CVE-2022-47175 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.3 – 1.3.70
- Fixed in:
- 1.3.71
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailC...
- Affected:
- up to 1.3.71
- Fixed in:
- 1.3.71
- Disclosed:
- Jul 18, 2023
CVE-2023-3709 on NVD →
Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp...
- CVSS:
- 5.3
- Affected:
- up to 1.3.70
- Fixed in:
- 1.3.71
- Disclosed:
- Jul 17, 2023
CVE-2023-3709 on NVD →
Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthentica...
- CVSS:
- 6.1
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4710 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates includ...
- CVSS:
- 5.4
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4704 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it...
- CVSS:
- 5.4
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4702 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If n...
- CVSS:
- 5.4
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4700 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4705 on NVD →
Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4707 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-librar...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4701 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4703 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates a...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4708 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any m...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4711 on NVD →
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin'...
- CVSS:
- 4.3
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4709 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthe...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4710 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates i...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4704 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4703 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the pl...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4709 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can t...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4707 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templa...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4708 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configura...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4705 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unles...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4702 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-l...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4701 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for...
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4711 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.60
unknown
[en] The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme....
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.60
- Disclosed:
- Jan 10, 2023
CVE-2022-4700 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56
unknown
[en] The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.
- Affected:
- up to 1.3.56
- Fixed in:
- 1.3.56
- Disclosed:
- Jan 9, 2023
CVE-2022-4102 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56
unknown
[en] The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title
- Affected:
- up to 1.3.56
- Fixed in:
- 1.3.56
- Disclosed:
- Jan 9, 2023
CVE-2022-4103 on NVD →
Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on the wpr_delete_template and wpr_create_template functions. This makes it possible for unauthenticated attackers to delete or creat...
- CVSS:
- 8.1
- Affected:
- up to 1.3.55
- Fixed in:
- 1.3.56
- Disclosed:
- Dec 15, 2022
CVE-2022-4102 on NVD →
Royal Elementor Addons <=1.3.55 - Authenticated (Subscriber+) Arbitrary Post Deletion
high
The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template deletion in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify whether the deleted post is a template. This makes it pos...
- CVSS:
- 8.1
- Affected:
- up to 1.3.55
- Fixed in:
- 1.3.56
- Disclosed:
- Dec 15, 2022
CVE-2022-4102 on NVD →
Royal Elementor Addons <=1.3.55 - Missing Authorization to Subscriber+ Arbitrary Post Creation
medium
The Royal Elementor Addons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check during template creation in the function wpr_create_template in versions up to, and including, 1.3.55. Furthermore, the plugin does not verify whether the created post is a template. This makes it pos...
- CVSS:
- 6.5
- Affected:
- up to 1.3.55
- Fixed in:
- 1.3.56
- Disclosed:
- Dec 15, 2022
CVE-2022-4103 on NVD →
Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery
high
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via forged request granted they...
- CVSS:
- 8.8
- Affected:
- up to 1.3.55
- Fixed in:
- 1.3.56
- Disclosed:
- Dec 6, 2022
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.56
unknown
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.55. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions via forged request granted they...
- Affected:
- up to 1.3.56
- Fixed in:
- 1.3.56
- Disclosed:
- Dec 6, 2022
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.3.33
- Fixed in:
- 1.3.33
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.33
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.3.33
- Fixed in:
- 1.3.33
- Disclosed:
- Mar 4, 2022
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.71
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.3.71
- Fixed in:
- 1.3.71
CVE-2023-33999 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1007
unknown
- Affected:
- up to 1.7.1007
- Fixed in:
- 1.7.1007
CVE-2025-0393 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1008
unknown
- Affected:
- up to 1.7.1008
- Fixed in:
- 1.7.1008
CVE-2025-1441 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1013
unknown
- Affected:
- up to 1.7.1013
- Fixed in:
- 1.7.1013
CVE-2025-1455 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1013
unknown
- Affected:
- up to 1.7.1013
- Fixed in:
- 1.7.1013
CVE-2025-1456 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1021
unknown
- Affected:
- up to 1.7.1021
- Fixed in:
- 1.7.1021
CVE-2025-3813 on NVD →
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1025
unknown
- Affected:
- up to 1.7.1025
- Fixed in:
- 1.7.1025
CVE-2025-5338 on NVD →