Extension WordPress

Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor

Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

82Vulnérabilités
1Critiques
82Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor

82 fiches

CVE-2026-8118 Moyenne · 6,5
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 – 1.7.1059 – Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as…

Versions affectées

1.7.1058-1.7.1059

Correctif

1.7.1060

Publication

18/06/2026

CVE-2026-6504 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1058 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.7.1058

Correctif

1.7.1059

Publication

13/05/2026

CVE-2026-27421 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1053 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

[*, 1.7.1053)

Correctif

1.7.1053

Publication

07/05/2026

CVE-2026-25436 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Missing Authorization

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.7.1053. This makes it possible…

Versions affectées

[*, 1.7.1053)

Correctif

1.7.1053

Publication

07/05/2026

CVE-2026-5159 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

04/05/2026

CVE-2026-4803 Élevée · 7,2
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1056 – Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

04/05/2026

CVE-2026-4024 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1056 – Missing Authorization to Unauthenticated Form Action Meta Modification

The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

01/05/2026

CVE-2026-6229 Élevée · 7,2
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1057 – Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by…

Versions affectées

*-1.7.1057

Correctif

1.7.1058

Publication

01/05/2026

CVE-2026-5428 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1056 – Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail()…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

23/04/2026

CVE-2026-5162 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

16/04/2026

CVE-2026-40720 Élevée · 7,2
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons < 1.7.1041 – Unauthenticated Stored Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

[*, 1.7.1041)

Correctif

1.7.1041

Publication

16/04/2026

CVE-2026-0664 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1049 – Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.7.1049

Correctif

1.7.1050

Publication

03/04/2026

CVE-2026-40763 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1056 – Missing Authorization

The Royal Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1056. This makes it possible for unauthenticated attackers to perform an…

Versions affectées

*-1.7.1056

Correctif

1.7.1057

Publication

31/03/2026

CVE-2026-2373 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 – Missing Authorization to Unauthenticated Custom Post Type Contents Exposure

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which…

Versions affectées

*-1.7.1049

Correctif

1.7.1050

Publication

16/03/2026

CVE-2025-13067 Élevée · 8,8
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor <= 1.7.1049 – Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with…

Versions affectées

*-1.7.1049

Correctif

1.7.1050

Publication

10/03/2026

CVE-2026-28135 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 – Missing Authorization

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1052. This…

Versions affectées

*-1.7.1052

Correctif

1.7.1053

Publication

26/02/2026

CVE-2025-11363 Moyenne · 5,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1036 – Missing Authorization to Unauthenticated Media File Upload

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized media file uploads due to a missing capability check on the 'wpr_addons_upload_file' AJAX endpoint in all versions up to,…

Versions affectées

*-1.7.1036

Correctif

1.7.1037

Publication

24/11/2025

CVE-2025-6251 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1036 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.7.1036

Correctif

1.7.1037

Publication

18/11/2025

CVE-2025-5338 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1028 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-1.7.1028

Correctif

1.7.1029

Publication

25/06/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités