Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesRoyal Addons for Elementor

Royal Addons for Elementor vulnerabilities

Royal Addons for Elementor has 69 known vulnerabilities in this database. The most recent published record is dated 12 Sep 2026.

Known vulnerabilities
69
Active installs
600,000+
Latest version
1.7.1068
Last updated
18 Sep 2026
Most recent
12 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-17585
Medium 5.3Up to 1.7.1066Fixed in a later version (latest 1.7.1068)12 Sep 2026
Cross-site scripting (XSS)
CVE-2026-19226
Medium 6.8Before 1.7.1066Fixed in 1.7.106626 Aug 2026
Broken access control
CVE-2026-13404
Medium 5.3Before 1.7.1066Fixed in 1.7.106626 Aug 2026
Broken access control
CVE-2026-13406
Medium 5.3Before 1.7.1066Fixed in 1.7.106626 Aug 2026
Remote code execution
CVE-2026-13405
Medium 6.6Before 1.7.1066Fixed in 1.7.106620 Aug 2026
Server-side request forgery (SSRF)
CVE-2026-17123
High 8.8Up to 1.7.1064Fixed in a later version (latest 1.7.1068)16 Aug 2026
Cross-site scripting (XSS)
CVE-2026-19217
Medium 5.4Before 1.7.1065Fixed in 1.7.106512 Aug 2026
Sensitive data exposure
CVE-2026-13402
Medium 5.3Before 1.7.1063Fixed in 1.7.106317 Jul 2026
Arbitrary file read
CVE-2026-8118
Medium 6.5Up to 1.7.1059Fixed in a later version (latest 1.7.1068)19 Jun 2026
Cross-site scripting (XSS)
CVE-2026-6504
Medium 6.4Up to 1.7.1058Fixed in a later version (latest 1.7.1068)14 May 2026
Cross-site scripting (XSS)
CVE-2026-4803
High 7.2Up to 1.7.1056Fixed in a later version (latest 1.7.1068)5 May 2026
Cross-site scripting (XSS)
CVE-2026-5159
Medium 6.4Up to 1.7.1056Fixed in a later version (latest 1.7.1068)5 May 2026
Broken access control
CVE-2026-4024
Medium 5.3Up to 1.7.1056Fixed in a later version (latest 1.7.1068)2 May 2026
Server-side request forgery (SSRF)
CVE-2026-6229
High 7.2Up to 1.7.1057Fixed in a later version (latest 1.7.1068)2 May 2026
Cross-site scripting (XSS)
CVE-2026-5428
Medium 6.4Up to 1.7.1056Fixed in a later version (latest 1.7.1068)24 Apr 2026
Cross-site scripting (XSS)
CVE-2026-5162
Medium 6.4Up to 1.7.1056Fixed in a later version (latest 1.7.1068)17 Apr 2026
Cross-site scripting (XSS)
CVE-2026-0664
Medium 6.4Up to 1.7.1049Fixed in a later version (latest 1.7.1068)4 Apr 2026
Broken access control
CVE-2026-2373
Medium 5.3Up to 1.7.1049Fixed in a later version (latest 1.7.1068)17 Mar 2026
Remote code execution
CVE-2025-13067
High 8.8Up to 1.7.1049Fixed in a later version (latest 1.7.1068)11 Mar 2026
Security weakness
CVE-2025-11363
Medium 5.3Before 1.7.1037Fixed in 1.7.103715 Dec 2025
Cross-site scripting (XSS)
CVE-2025-6251
Medium 6.4Up to 1.7.1036Fixed in a later version (latest 1.7.1068)19 Nov 2025
Cross-site scripting (XSS)
CVE-2025-5338
Medium 6.4Before 1.7.1025Fixed in 1.7.102526 Jun 2025
Cross-site scripting (XSS)
CVE-2025-3813
Medium 6.4Before 1.7.1021Fixed in 1.7.102131 May 2025
Cross-site scripting (XSS)
CVE-2024-12120
Medium 5.4Before 1.7.1018Fixed in 1.7.10187 May 2025
Cross-site scripting (XSS)
CVE-2025-1456
Medium 6.4Before 1.7.1013Fixed in 1.7.101312 Apr 2025
Cross-site scripting (XSS)
CVE-2025-1455
Medium 6.4Before 1.7.1013Fixed in 1.7.101312 Apr 2025
Cross-site request forgery (CSRF)
CVE-2025-1441
Medium 6.1Up to 1.7.1007Fixed in a later version (latest 1.7.1068)19 Feb 2025
Cross-site request forgery (CSRF)
CVE-2025-0393
Medium 6.1Up to 1.7.1006Fixed in a later version (latest 1.7.1068)14 Jan 2025
Broken access control
CVE-2024-10798
Medium 4.3Up to 1.7.1003Fixed in a later version (latest 1.7.1068)28 Nov 2024
Cross-site scripting (XSS)
CVE-2024-9668
Medium 6.4Before 1.7.1002Fixed in 1.7.100213 Nov 2024
Cross-site scripting (XSS)
CVE-2024-9682
Medium 6.4Before 1.7.1002Fixed in 1.7.100213 Nov 2024
Cross-site scripting (XSS)
CVE-2024-9059
Medium 6.4Before 1.7.1002Fixed in 1.7.100213 Nov 2024
Sensitive data exposure
CVE-2024-7417
Medium 4.3Up to 1.3.986Fixed in a later version (latest 1.7.1068)17 Oct 2024
Cross-site scripting (XSS)
CVE-2024-8482
Medium 6.4Before 1.3.987Fixed in 1.3.9878 Oct 2024
Cross-site scripting (XSS)
CVE-2024-5818
Medium 6.4Before 1.3.981Fixed in 1.3.98124 Jul 2024
Cross-site scripting (XSS)
CVE-2024-4488
Medium 6.4Before 1.3.977Fixed in 1.3.9777 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4489
Medium 6.4Before 1.3.977Fixed in 1.3.9777 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4342
Medium 6.4Before 1.3.976Fixed in 1.3.9761 Jun 2024
Cross-site scripting (XSS)
CVE-2024-4087
Medium 6.4Before 1.3.976Fixed in 1.3.9761 Jun 2024
Cross-site scripting (XSS)
CVE-2024-3887
Medium 5.4Before 1.3.975Fixed in 1.3.97516 May 2024
Cross-site scripting (XSS)
CVE-2024-3675
Medium 6.4Before 1.3.972Fixed in 1.3.9722 May 2024
Cross-site scripting (XSS)
CVE-2024-1567
High 8.2Before 1.3.95Fixed in 1.3.952 May 2024
Cross-site scripting (XSS)
CVE-2024-2798
Medium 6.4Before 1.3.972Fixed in 1.3.97223 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2799
Medium 6.4Before 1.3.97Fixed in 1.3.9723 Apr 2024
Cross-site scripting (XSS)
CVE-2024-3889
Medium 6.4Before 1.3.972Fixed in 1.3.97223 Apr 2024
Cross-site scripting (XSS)
CVE-2024-1500
Medium 5.4Before 1.3.92Fixed in 1.3.927 Mar 2024
Cross-site request forgery (CSRF)
CVE-2024-0514
Medium 4.3Before 1.3.88Fixed in 1.3.8829 Feb 2024
Cross-site request forgery (CSRF)
CVE-2024-0515
Medium 4.3Before 1.3.88Fixed in 1.3.8829 Feb 2024
Broken access control
CVE-2024-0516
Medium 5.3Before 1.3.88Fixed in 1.3.8829 Feb 2024
Cross-site request forgery (CSRF)
CVE-2024-0512
Medium 4.3Before 1.3.88Fixed in 1.3.8829 Feb 2024
Cross-site request forgery (CSRF)
CVE-2024-0513
Medium 4.3Before 1.3.88Fixed in 1.3.8829 Feb 2024
Cross-site scripting (XSS)
CVE-2024-0442
Medium 6.4Before 1.3.88Fixed in 1.3.8829 Feb 2024
Cross-site request forgery (CSRF)
CVE-2024-0511
Medium 4.3Before 1.3.88Fixed in 1.3.888 Feb 2024
Security weakness
CVE-2023-5922
High 7.5Before 1.3.81Fixed in 1.3.8116 Jan 2024
Remote code execution
CVE-2023-5360
Critical 9.8Before 1.3.79Fixed in 1.3.7931 Oct 2023
Sensitive data exposure
CVE-2023-3709
Medium 5.3Up to 1.3.70Fixed in a later version (latest 1.7.1068)18 Jul 2023
Broken access control
CVE-2022-4700
Medium 5.4Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4701
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4702
Medium 5.4Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4703
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4704
Medium 5.4Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4705
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Cross-site request forgery (CSRF)
CVE-2022-4707
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4708
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4709
Medium 4.3Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Cross-site scripting (XSS)
CVE-2022-4710
Medium 6.1Up to 1.3.59Fixed in a later version (latest 1.7.1068)10 Jan 2023
Broken access control
CVE-2022-4711
Medium 4.3Before 1.3.60Fixed in 1.3.6010 Jan 2023
Cross-site request forgery (CSRF)
CVE-2022-4102
Low 3.1Before 1.3.56Fixed in 1.3.569 Jan 2023
Cross-site request forgery (CSRF)
CVE-2022-4103
Medium 4.3Before 1.3.56Fixed in 1.3.569 Jan 2023
Read the published descriptions
CVE-2026-17585, 12 Sep 2026
The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it. CVE record
CVE-2026-19226, 26 Aug 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
CVE-2026-13404, 26 Aug 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts. CVE record
CVE-2026-13406, 26 Aug 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies. CVE record
CVE-2026-13405, 20 Aug 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code. CVE record
CVE-2026-17123, 16 Aug 2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhook AJAX handler - registered for both authenticated and unauthenticated callers - reads that option and dispatches the outbound request via the non-safe wp_remote_post(), with no host allowlist, no scheme restriction, and no private/loopback IP filter (the plugin's existing wpr_is_blocked_remote_host / wpr_is_private_or_local_ip helpers are not called on this path). This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
CVE-2026-19217, 12 Aug 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
CVE-2026-13402, 17 Jul 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items. CVE record
CVE-2026-8118, 19 Jun 2026
The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back to is_readable() and fopen($source, 'r') on the attacker-controlled settings.table_upload_csv.url value when it does not parse as an HTTP URL, with no allow-list, traversal block, or extension check. This makes it possible for authenticated attackers, with Contributor-level access and above, to save a crafted wpr-data-table widget through Elementor's save_builder endpoint and have the rendered preview return the line-by-line contents of any file readable by the PHP process, including wp-config.php. CVE record
CVE-2026-6504, 14 May 2026
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-4803, 5 May 2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce that allows unauthenticated access to the AJAX handler. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-5159, 5 May 2026
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that exploitation requires that an administrator has previously configured the Instagram Feed widget with a valid Instagram access token on the site. CVE record
CVE-2026-4024, 2 May 2026
The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax` and `wp_ajax_nopriv` hooks, making it accessible to unauthenticated users. Although a nonce is verified, the nonce (`wpr-addons-js`) is publicly exposed in frontend JavaScript via `WprConfig.nonce` on any page that loads Royal Addons widgets, rendering the protection ineffective. The endpoint also lacks any capability or ownership checks and directly calls `update_post_meta()` with user-controlled input on a whitelisted set of form action meta keys. This makes it possible for unauthenticated attackers to modify form action configuration metadata (email, submissions, Mailchimp, and webhook settings) on any post, potentially leading to webhook/email action tampering and data exfiltration via modified webhook URLs. CVE record
CVE-2026-6229, 2 May 2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking internal or private network addresses. This makes it possible for authenticated attackers, with Contributor-level access and above, to make requests to arbitrary URLs and retrieve sensitive information from internal services. CVE record
CVE-2026-5428, 24 Apr 2026
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page with the malicious image displayed in the media grid widget. CVE record
CVE-2026-5162, 17 Apr 2026
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-0664, 4 Apr 2026
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-2373, 17 Mar 2026
The Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons. CVE record
CVE-2025-13067, 11 Mar 2026
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
CVE-2025-11363, 15 Dec 2025
The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action. CVE record
CVE-2025-6251, 19 Nov 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-5338, 26 Jun 2025
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-3813, 31 May 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-12120, 7 May 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-1456, 12 Apr 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-1455, 12 Apr 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-1441, 19 Feb 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2025-0393, 14 Jan 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-10798, 28 Nov 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created via Elementor that they should not have access to. CVE record
CVE-2024-9668, 13 Nov 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-9682, 13 Nov 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-9059, 13 Nov 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-7417, 17 Oct 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts. CVE record
CVE-2024-8482, 8 Oct 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-5818, 24 Jul 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4488, 7 Jun 2024
The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4489, 7 Jun 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4342, 1 Jun 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4087, 1 Jun 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3887, 16 May 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3675, 2 May 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1567, 2 May 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible. CVE record
CVE-2024-2798, 23 Apr 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2799, 23 Apr 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3889, 23 Apr 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-1500, 7 Mar 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0514, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes it possible for unauthenticated attackers to add items to user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-0515, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it possible for unauthenticated attackers to remove items from user compare lists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-0516, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata. CVE record
CVE-2024-0512, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes it possible for unauthenticated attackers to add items to user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-0513, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_wishlist function. This makes it possible for unauthenticated attackers to remove items from user wishlists via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-0442, 29 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-0511, 8 Feb 2024
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-5922, 16 Jan 2024
The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content CVE record
CVE-2023-5360, 31 Oct 2023
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE. CVE record
CVE-2023-3709, 18 Jul 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp API key. We recommend resetting any MailChimp API keys if running a vulnerable version of this plugin with the MailChimp block enabled as the API key may have been compromised. CVE record
CVE-2022-4700, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme. CVE record
CVE-2022-4701, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7', 'media-library-assistant', or 'woocommerce' plugins if they are installed on the site. CVE record
CVE-2022-4702, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues. CVE record
CVE-2022-4703, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data. CVE record
CVE-2022-4704, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates including images and settings. CVE record
CVE-2022-4705, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration templates, which can be chosen and imported via a separate action documented in CVE-2022-4704. CVE record
CVE-2022-4707, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX function. This allows unauthenticated attackers to create Mega Menu templates, granted they can trick an administrator into performing an action, such as clicking a link. CVE record
CVE-2022-4708, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed. CVE record
CVE-2022-4709, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library. CVE record
CVE-2022-4710, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.59, due to due to insufficient input sanitization and output escaping of the 'wpr_ajax_search_link_target' parameter in the 'data_fetch' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is occurring because 'sanitize_text_field' is insufficient to prevent attribute-based Cross-Site Scripting CVE record
CVE-2022-4711, 10 Jan 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to enable and modify Mega Menu settings for any menu item. CVE record
CVE-2022-4102, 9 Jan 2023
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug. CVE record
CVE-2022-4103, 9 Jan 2023
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title CVE record

What to do if you run Royal Addons for Elementor

If you run Royal Addons for Elementor, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Royal Addons for Elementor vulnerabilities

Free. We email you when a new vulnerability is published for Royal Addons for Elementor, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support