HomeWordPress vulnerabilitiesRoyal Addons for Elementor
Royal Addons for Elementor vulnerabilities
Royal Addons for Elementor has 69 known vulnerabilities in this database. The most recent published record is dated 12 Sep 2026.
- Known vulnerabilities
- 69
- Active installs
- 600,000+
- Latest version
- 1.7.1068
- Last updated
- 18 Sep 2026
- Most recent
- 12 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-17585 | Medium 5.3 | Up to 1.7.1066 | Fixed in a later version (latest 1.7.1068) | 12 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-19226 | Medium 6.8 | Before 1.7.1066 | Fixed in 1.7.1066 | 26 Aug 2026 |
| Broken access control CVE-2026-13404 | Medium 5.3 | Before 1.7.1066 | Fixed in 1.7.1066 | 26 Aug 2026 |
| Broken access control CVE-2026-13406 | Medium 5.3 | Before 1.7.1066 | Fixed in 1.7.1066 | 26 Aug 2026 |
| Remote code execution CVE-2026-13405 | Medium 6.6 | Before 1.7.1066 | Fixed in 1.7.1066 | 20 Aug 2026 |
| Server-side request forgery (SSRF) CVE-2026-17123 | High 8.8 | Up to 1.7.1064 | Fixed in a later version (latest 1.7.1068) | 16 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-19217 | Medium 5.4 | Before 1.7.1065 | Fixed in 1.7.1065 | 12 Aug 2026 |
| Sensitive data exposure CVE-2026-13402 | Medium 5.3 | Before 1.7.1063 | Fixed in 1.7.1063 | 17 Jul 2026 |
| Arbitrary file read CVE-2026-8118 | Medium 6.5 | Up to 1.7.1059 | Fixed in a later version (latest 1.7.1068) | 19 Jun 2026 |
| Cross-site scripting (XSS) CVE-2026-6504 | Medium 6.4 | Up to 1.7.1058 | Fixed in a later version (latest 1.7.1068) | 14 May 2026 |
| Cross-site scripting (XSS) CVE-2026-4803 | High 7.2 | Up to 1.7.1056 | Fixed in a later version (latest 1.7.1068) | 5 May 2026 |
| Cross-site scripting (XSS) CVE-2026-5159 | Medium 6.4 | Up to 1.7.1056 | Fixed in a later version (latest 1.7.1068) | 5 May 2026 |
| Broken access control CVE-2026-4024 | Medium 5.3 | Up to 1.7.1056 | Fixed in a later version (latest 1.7.1068) | 2 May 2026 |
| Server-side request forgery (SSRF) CVE-2026-6229 | High 7.2 | Up to 1.7.1057 | Fixed in a later version (latest 1.7.1068) | 2 May 2026 |
| Cross-site scripting (XSS) CVE-2026-5428 | Medium 6.4 | Up to 1.7.1056 | Fixed in a later version (latest 1.7.1068) | 24 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-5162 | Medium 6.4 | Up to 1.7.1056 | Fixed in a later version (latest 1.7.1068) | 17 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-0664 | Medium 6.4 | Up to 1.7.1049 | Fixed in a later version (latest 1.7.1068) | 4 Apr 2026 |
| Broken access control CVE-2026-2373 | Medium 5.3 | Up to 1.7.1049 | Fixed in a later version (latest 1.7.1068) | 17 Mar 2026 |
| Remote code execution CVE-2025-13067 | High 8.8 | Up to 1.7.1049 | Fixed in a later version (latest 1.7.1068) | 11 Mar 2026 |
| Security weakness CVE-2025-11363 | Medium 5.3 | Before 1.7.1037 | Fixed in 1.7.1037 | 15 Dec 2025 |
| Cross-site scripting (XSS) CVE-2025-6251 | Medium 6.4 | Up to 1.7.1036 | Fixed in a later version (latest 1.7.1068) | 19 Nov 2025 |
| Cross-site scripting (XSS) CVE-2025-5338 | Medium 6.4 | Before 1.7.1025 | Fixed in 1.7.1025 | 26 Jun 2025 |
| Cross-site scripting (XSS) CVE-2025-3813 | Medium 6.4 | Before 1.7.1021 | Fixed in 1.7.1021 | 31 May 2025 |
| Cross-site scripting (XSS) CVE-2024-12120 | Medium 5.4 | Before 1.7.1018 | Fixed in 1.7.1018 | 7 May 2025 |
| Cross-site scripting (XSS) CVE-2025-1456 | Medium 6.4 | Before 1.7.1013 | Fixed in 1.7.1013 | 12 Apr 2025 |
| Cross-site scripting (XSS) CVE-2025-1455 | Medium 6.4 | Before 1.7.1013 | Fixed in 1.7.1013 | 12 Apr 2025 |
| Cross-site request forgery (CSRF) CVE-2025-1441 | Medium 6.1 | Up to 1.7.1007 | Fixed in a later version (latest 1.7.1068) | 19 Feb 2025 |
| Cross-site request forgery (CSRF) CVE-2025-0393 | Medium 6.1 | Up to 1.7.1006 | Fixed in a later version (latest 1.7.1068) | 14 Jan 2025 |
| Broken access control CVE-2024-10798 | Medium 4.3 | Up to 1.7.1003 | Fixed in a later version (latest 1.7.1068) | 28 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-9668 | Medium 6.4 | Before 1.7.1002 | Fixed in 1.7.1002 | 13 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-9682 | Medium 6.4 | Before 1.7.1002 | Fixed in 1.7.1002 | 13 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-9059 | Medium 6.4 | Before 1.7.1002 | Fixed in 1.7.1002 | 13 Nov 2024 |
| Sensitive data exposure CVE-2024-7417 | Medium 4.3 | Up to 1.3.986 | Fixed in a later version (latest 1.7.1068) | 17 Oct 2024 |
| Cross-site scripting (XSS) CVE-2024-8482 | Medium 6.4 | Before 1.3.987 | Fixed in 1.3.987 | 8 Oct 2024 |
| Cross-site scripting (XSS) CVE-2024-5818 | Medium 6.4 | Before 1.3.981 | Fixed in 1.3.981 | 24 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-4488 | Medium 6.4 | Before 1.3.977 | Fixed in 1.3.977 | 7 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4489 | Medium 6.4 | Before 1.3.977 | Fixed in 1.3.977 | 7 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4342 | Medium 6.4 | Before 1.3.976 | Fixed in 1.3.976 | 1 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-4087 | Medium 6.4 | Before 1.3.976 | Fixed in 1.3.976 | 1 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-3887 | Medium 5.4 | Before 1.3.975 | Fixed in 1.3.975 | 16 May 2024 |
| Cross-site scripting (XSS) CVE-2024-3675 | Medium 6.4 | Before 1.3.972 | Fixed in 1.3.972 | 2 May 2024 |
| Cross-site scripting (XSS) CVE-2024-1567 | High 8.2 | Before 1.3.95 | Fixed in 1.3.95 | 2 May 2024 |
| Cross-site scripting (XSS) CVE-2024-2798 | Medium 6.4 | Before 1.3.972 | Fixed in 1.3.972 | 23 Apr 2024 |
| Cross-site scripting (XSS) CVE-2024-2799 | Medium 6.4 | Before 1.3.97 | Fixed in 1.3.97 | 23 Apr 2024 |
| Cross-site scripting (XSS) CVE-2024-3889 | Medium 6.4 | Before 1.3.972 | Fixed in 1.3.972 | 23 Apr 2024 |
| Cross-site scripting (XSS) CVE-2024-1500 | Medium 5.4 | Before 1.3.92 | Fixed in 1.3.92 | 7 Mar 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0514 | Medium 4.3 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0515 | Medium 4.3 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Broken access control CVE-2024-0516 | Medium 5.3 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0512 | Medium 4.3 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0513 | Medium 4.3 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Cross-site scripting (XSS) CVE-2024-0442 | Medium 6.4 | Before 1.3.88 | Fixed in 1.3.88 | 29 Feb 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0511 | Medium 4.3 | Before 1.3.88 | Fixed in 1.3.88 | 8 Feb 2024 |
| Security weakness CVE-2023-5922 | High 7.5 | Before 1.3.81 | Fixed in 1.3.81 | 16 Jan 2024 |
| Remote code execution CVE-2023-5360 | Critical 9.8 | Before 1.3.79 | Fixed in 1.3.79 | 31 Oct 2023 |
| Sensitive data exposure CVE-2023-3709 | Medium 5.3 | Up to 1.3.70 | Fixed in a later version (latest 1.7.1068) | 18 Jul 2023 |
| Broken access control CVE-2022-4700 | Medium 5.4 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4701 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4702 | Medium 5.4 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4703 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4704 | Medium 5.4 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4705 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Cross-site request forgery (CSRF) CVE-2022-4707 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4708 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4709 | Medium 4.3 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Cross-site scripting (XSS) CVE-2022-4710 | Medium 6.1 | Up to 1.3.59 | Fixed in a later version (latest 1.7.1068) | 10 Jan 2023 |
| Broken access control CVE-2022-4711 | Medium 4.3 | Before 1.3.60 | Fixed in 1.3.60 | 10 Jan 2023 |
| Cross-site request forgery (CSRF) CVE-2022-4102 | Low 3.1 | Before 1.3.56 | Fixed in 1.3.56 | 9 Jan 2023 |
| Cross-site request forgery (CSRF) CVE-2022-4103 | Medium 4.3 | Before 1.3.56 | Fixed in 1.3.56 | 9 Jan 2023 |
Read the published descriptions
- CVE-2026-17585, 12 Sep 2026
- The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it. CVE record
- CVE-2026-19226, 26 Aug 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
- CVE-2026-13404, 26 Aug 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts. CVE record
- CVE-2026-13406, 26 Aug 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies. CVE record
- CVE-2026-13405, 20 Aug 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code. CVE record
- CVE-2026-17123, 16 Aug 2026
- The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhook AJAX handler - registered for both authenticated and unauthenticated callers - reads that option and dispatches the outbound request via the non-safe wp_remote_post(), with no host allowlist, no scheme restriction, and no private/loopback IP filter (the plugin's existing wpr_is_blocked_remote_host / wpr_is_private_or_local_ip helpers are not called on this path). This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
- CVE-2026-19217, 12 Aug 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
- CVE-2026-13402, 17 Jul 2026
- The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items. CVE record
- CVE-2026-8118, 19 Jun 2026
- The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable() and fopen($source, 'r') on the attacker-controlled settings.table_upload_csv.url value when it does not parse as an HTTP URL, with no allow-list, traversal block, or extension check. This makes it possible for authenticated attackers, with Contributor-level access and above, to save a crafted wpr-data-table widget through Elementor's save_builder endpoint and have the rendered preview return the line-by-line contents of any file readable by the PHP process, including wp-config.php. CVE record
- CVE-2026-6504, 14 May 2026
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-4803, 5 May 2026
- The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce that allows unauthenticated access to the AJAX handler. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-5159, 5 May 2026
- The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that exploitation requires that an administrator has previously configured the Instagram Feed widget with a valid Instagram access token on the site. CVE record
- CVE-2026-4024, 2 May 2026
- The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it accessible to unauthenticated users. Although a nonce is verified, the nonce (`wpr-addons-js`) is publicly exposed in frontend JavaScript via `WprConfig.nonce` on any page that loads Royal Addons widgets, rendering the protection ineffective. The endpoint also lacks any capability or ownership checks and directly calls `update_post_meta()` with user-controlled input on a whitelisted set of form action meta keys. This makes it possible for unauthenticated attackers to modify form action configuration metadata (email, submissions, Mailchimp, and webhook settings) on any post, potentially leading to webhook/email action tampering and data exfiltration via modified webhook URLs. CVE record
- CVE-2026-6229, 2 May 2026
- The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking internal or private network addresses. This makes it possible for authenticated attackers, with Contributor-level access and above, to make requests to arbitrary URLs and retrieve sensitive information from internal services. CVE record
- CVE-2026-5428, 24 Apr 2026
- The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page with the malicious image displayed in the media grid widget. CVE record
- CVE-2026-5162, 17 Apr 2026
- The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-0664, 4 Apr 2026
- The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-2373, 17 Mar 2026
- The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons. CVE record
- CVE-2025-13067, 11 Mar 2026
- The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2025-11363, 15 Dec 2025
- The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action. CVE record
- CVE-2025-6251, 19 Nov 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-5338, 26 Jun 2025
- The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-3813, 31 May 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-12120, 7 May 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-1456, 12 Apr 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-1455, 12 Apr 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-1441, 19 Feb 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2025-0393, 14 Jan 2025
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-10798, 28 Nov 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to. CVE record
- CVE-2024-9668, 13 Nov 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-9682, 13 Nov 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-9059, 13 Nov 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-7417, 17 Oct 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts. CVE record
- CVE-2024-8482, 8 Oct 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-5818, 24 Jul 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4488, 7 Jun 2024
- The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4489, 7 Jun 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4342, 1 Jun 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-4087, 1 Jun 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3887, 16 May 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3675, 2 May 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1567, 2 May 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible. CVE record
- CVE-2024-2798, 23 Apr 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2799, 23 Apr 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3889, 23 Apr 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1500, 7 Mar 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-0514, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-0515, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-0516, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata. CVE record
- CVE-2024-0512, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-0513, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-0442, 29 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-0511, 8 Feb 2024
- The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-5922, 16 Jan 2024
- The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content CVE record
- CVE-2023-5360, 31 Oct 2023
- The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE. CVE record
- CVE-2023-3709, 18 Jul 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. CVE record
- CVE-2022-4700, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme. CVE record
- CVE-2022-4701, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-library-assistant', or 'woocommerce' plugins if they are installed on the site. CVE record
- CVE-2022-4702, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues. CVE record
- CVE-2022-4703, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data. CVE record
- CVE-2022-4704, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates including images and settings. CVE record
- CVE-2022-4705, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration templates, which can be chosen and imported via a separate action documented in CVE-2022-4704. CVE record
- CVE-2022-4707, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can trick an administrator into performing an action, such as clicking a link. CVE record
- CVE-2022-4708, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed. CVE record
- CVE-2022-4709, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library. CVE record
- CVE-2022-4710, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is occurring because 'sanitize_text_field' is insufficient to prevent attribute-based Cross-Site Scripting CVE record
- CVE-2022-4711, 10 Jan 2023
- The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any menu item. CVE record
- CVE-2022-4102, 9 Jan 2023
- The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug. CVE record
- CVE-2022-4103, 9 Jan 2023
- The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title CVE record
What to do if you run Royal Addons for Elementor
If you run Royal Addons for Elementor, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Royal Addons for Elementor vulnerabilities
Free. We email you when a new vulnerability is published for Royal Addons for Elementor, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.