📦 Royal Elementor Addons

by Royal Elementor Addons

🔍 What is Royal Elementor Addons?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-5360

CRITICAL CVSS 9.8 Oct 31, 2023

This vulnerability in the Royal Elementor Addons and Templates WordPress plugin allows unauthenticated attackers to upload arbitrary files, including PHP shells, leading to remote code execution. It a...

CVE-2024-56226

HIGH CVSS 7.1 Dec 31, 2024

This reflected cross-site scripting (XSS) vulnerability in the Royal Elementor Addons WordPress plugin allows attackers to inject malicious scripts into web pages. When exploited, it can enable sessio...

CVE-2024-1567

HIGH CVSS 8.2 May 2, 2024

The Royal Elementor Addons and Templates WordPress plugin has a vulnerability that allows unauthenticated attackers to upload dangerous file types like .svgz due to missing file type validation. This ...

CVE-2023-5922

HIGH CVSS 7.5 Jan 16, 2024

This vulnerability in the Royal Elementor Addons and Templates WordPress plugin allows unauthenticated attackers to access draft, private, and password-protected posts/pages via AJAX endpoints. Any Wo...

CVE-2025-1456

MEDIUM CVSS 6.4 Apr 12, 2025

This stored XSS vulnerability in the Royal Elementor Addons WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into website pages. The ...

CVE-2025-1441

MEDIUM CVSS 6.1 Feb 19, 2025

This CSRF vulnerability in the Royal Elementor Addons WordPress plugin allows attackers to inject malicious scripts by tricking administrators into clicking malicious links. All WordPress sites using ...

CVE-2024-10798

MEDIUM CVSS 4.3 Nov 28, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to extract data from private or draft posts created via Elementor that they should not have access to. I...

CVE-2024-9682

MEDIUM CVSS 6.4 Nov 13, 2024

This stored XSS vulnerability in Royal Elementor Addons plugin allows authenticated attackers with contributor access or higher to inject malicious scripts into WordPress pages. The scripts execute wh...

CVE-2024-9059

MEDIUM CVSS 6.4 Nov 13, 2024

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious scripts into pages using the Royal Elementor Addons plugin's Google Maps widget. The...

CVE-2024-7417

MEDIUM CVSS 4.3 Oct 17, 2024

This vulnerability in the Royal Elementor Addons and Templates WordPress plugin allows authenticated attackers with subscriber-level access or higher to bypass password protection and view content fro...

CVE-2024-8482

MEDIUM CVSS 6.4 Oct 8, 2024

This stored XSS vulnerability in the Royal Elementor Addons WordPress plugin allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into website pages. The ...

CVE-2024-44001

MEDIUM CVSS 6.5 Sep 18, 2024

This stored XSS vulnerability in the Royal Elementor Addons WordPress plugin allows attackers to inject malicious scripts into web pages. When users view compromised pages, the scripts execute in thei...

CVE-2024-5818

MEDIUM CVSS 6.4 Jul 24, 2024

This vulnerability allows authenticated WordPress users with contributor-level access or higher to inject malicious scripts into pages using the Royal Elementor Addons plugin's Magazine Grid/Slider wi...

CVE-2024-4489

MEDIUM CVSS 6.4 Jun 7, 2024

The Royal Elementor Addons and Templates WordPress plugin has a stored XSS vulnerability that allows authenticated attackers with contributor-level permissions or higher to inject malicious scripts in...

CVE-2024-4342

MEDIUM CVSS 6.4 Jun 1, 2024

The Royal Elementor Addons and Templates WordPress plugin has a stored XSS vulnerability in multiple widgets. Authenticated attackers with contributor-level access or higher can inject malicious scrip...

CVE-2024-32786

MEDIUM CVSS 5.3 May 17, 2024

This CVE describes an authentication bypass vulnerability in the Royal Elementor Addons WordPress plugin that allows attackers to spoof IP addresses and bypass intended functionality restrictions. It ...

CVE-2024-3675

MEDIUM CVSS 6.4 May 2, 2024

This stored XSS vulnerability in the Royal Elementor Addons WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages. The scri...