Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
86 fiches
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 – Authenticated (Administrator+) Remote Code Execution
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.7.1066. This is due to insufficient validation of user supplied input before…
[*, 1.7.1066)
1.7.1066
21/08/2026
Royal Addons for Elementor <= 1.7.1064 – Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id}…
*-1.7.1064
1.7.1065
15/08/2026
Royal Elementor Addons <= 1.7.1064 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1064 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.7.1064
1.7.1065
10/08/2026
Royal Elementor Addons <= 1.7.1062 – Unauthenticated Information Exposure
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1062. This makes it possible for unauthenticated attackers to extract…
*-1.7.1062
1.7.1063
26/06/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 – 1.7.1059 – Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as…
1.7.1058-1.7.1059
1.7.1060
18/06/2026
Royal Addons for Elementor <= 1.7.1058 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it…
*-1.7.1058
1.7.1059
13/05/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1053 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 1.7.1053)
1.7.1053
07/05/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Missing Authorization
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.7.1053. This makes it possible…
[*, 1.7.1053)
1.7.1053
07/05/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…
*-1.7.1056
1.7.1057
04/05/2026
Royal Addons for Elementor <= 1.7.1056 – Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and…
*-1.7.1056
1.7.1057
04/05/2026
Royal Addons for Elementor <= 1.7.1056 – Missing Authorization to Unauthenticated Form Action Meta Modification
The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered…
*-1.7.1056
1.7.1057
01/05/2026
Royal Addons for Elementor <= 1.7.1057 – Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by…
*-1.7.1057
1.7.1058
01/05/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail()…
*-1.7.1056
1.7.1057
23/04/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…
*-1.7.1056
1.7.1057
16/04/2026
Royal Elementor Addons < 1.7.1041 – Unauthenticated Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
[*, 1.7.1041)
1.7.1041
16/04/2026
Royal Elementor Addons <= 1.7.1049 – Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.7.1049
1.7.1050
03/04/2026
Royal Elementor Addons <= 1.7.1056 – Missing Authorization
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1056. This makes it possible for unauthenticated attackers to perform an…
*-1.7.1056
1.7.1057
31/03/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 – Missing Authorization to Unauthenticated Custom Post Type Contents Exposure
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which…
*-1.7.1049
1.7.1050
16/03/2026
Royal Addons for Elementor <= 1.7.1049 – Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with…
*-1.7.1049
1.7.1050
10/03/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 – Missing Authorization
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1052. This…
*-1.7.1052
1.7.1053
26/02/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.