Product
royal elementor addons royal elementor addons
59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5338
CVE-2025-3813
CVE-2025-39361
CVE-2024-12120
CVE-2025-26990
CVE-2025-1456
CVE-2025-1455
CVE-2025-1441
CVE-2025-0393
CVE-2024-56062
CVE-2024-56227
CVE-2024-56226
CVE-2024-10798
CVE-2024-9682
CVE-2024-9668
CVE-2024-9059
CVE-2024-50442
CVE-2024-7417
CVE-2024-8482
CVE-2024-44001
CVE-2024-5818
CVE-2024-4489
CVE-2024-4488
CVE-2024-4342
CVE-2024-4087
CVE-2024-32786
CVE-2024-3887
CVE-2024-3675
CVE-2024-1567
CVE-2024-3889
CVE-2024-2799
CVE-2024-2798
CVE-2024-31236
CVE-2024-1500
CVE-2024-0516
CVE-2024-0515
CVE-2024-0514
CVE-2024-0513
CVE-2024-0512
CVE-2024-0442
CVE-2024-0511
CVE-2024-0835
CVE-2023-5922
CVE-2023-5360
CVE-2022-47175
CVE-2023-3709
CVE-2022-4711
CVE-2022-4710
CVE-2022-4709
CVE-2022-4708
CVE-2022-4707
CVE-2022-4705
CVE-2022-4704
CVE-2022-4703
CVE-2022-4702
CVE-2022-4701
CVE-2022-4700
CVE-2022-4103
CVE-2022-4102
< 1.7.1025
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions
< 1.7.1021
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_d
< 1.7.1018
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Elementor Add
< 1.7.1018
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widge
< 1.7.1007
Server-Side Request Forgery (SSRF) vulnerability in WP Royal Elementor Addons royal-elementor-addons allows Server Side Requ
< 1.7.1013
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
widgetGrid, `< 1.7.1013
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget
<= 1.7.1007
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
<= 1.7.1006
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
<= 1.3.987
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Elementor Add
< 1.7.1002
Missing Authorization vulnerability in WP Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Config
< 1.7.1002
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Elementor Add
<= 1.7.1003
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc
< 1.7.1002
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form B
< 1.7.1002
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countd
< 1.7.1002
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps wid
< 1.3.981
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Elementor Addons royal-elementor-addons allo
<= 1.3.986
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc
< 1.3.987
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ param
<= 1.3.982
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Elementor Add
< 1.3.981
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugi
< 1.3.977
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_uploa
< 1.3.977
The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ para
< 1.3.976
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image
< 1.3.976
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back t
< 1.3.95
Authentication Bypass by Spoofing vulnerability in WP Royal Elementor Addons allows Functionality Bypass.This issue affects
< 1.3.975
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder wi
< 1.3.972
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip C
< 1.3.95
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type valid
< 1.3.972
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanc
< 1.3.97
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Ad
< 1.3.972
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget
< 1.3.94
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Elementor Add
< 1.3.92
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL paramet
< 1.3.88
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
<= 1.0.116
The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability c
< 1.3.81
The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX act
< 1.3.79
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could all
<= 1.3.75
Cross-Site Request Forgery (CSRF) vulnerability in P Royal Elementor Addons and Templates plugin <= 1.3.75 versions.
<= 1.3.70
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and includi
< 1.3.60
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings'
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template'
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions'
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJA
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJA
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJ
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility'
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins
<= 1.3.59
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme'
< 1.3.56
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, an
< 1.3.56
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and