Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
82 fiches
Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 – 1.7.1059 – Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as…
1.7.1058-1.7.1059
1.7.1060
18/06/2026
Royal Addons for Elementor <= 1.7.1058 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it…
*-1.7.1058
1.7.1059
13/05/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1053 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 1.7.1053)
1.7.1053
07/05/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 – Missing Authorization
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.7.1053. This makes it possible…
[*, 1.7.1053)
1.7.1053
07/05/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…
*-1.7.1056
1.7.1057
04/05/2026
Royal Addons for Elementor <= 1.7.1056 – Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and…
*-1.7.1056
1.7.1057
04/05/2026
Royal Addons for Elementor <= 1.7.1056 – Missing Authorization to Unauthenticated Form Action Meta Modification
The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered…
*-1.7.1056
1.7.1057
01/05/2026
Royal Addons for Elementor <= 1.7.1057 – Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by…
*-1.7.1057
1.7.1058
01/05/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail()…
*-1.7.1056
1.7.1057
23/04/2026
Royal Addons for Elementor <= 1.7.1056 – Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, 1.7.1056 due to insufficient input sanitization and output escaping. This…
*-1.7.1056
1.7.1057
16/04/2026
Royal Elementor Addons < 1.7.1041 – Unauthenticated Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
[*, 1.7.1041)
1.7.1041
16/04/2026
Royal Elementor Addons <= 1.7.1049 – Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.7.1049
1.7.1050
03/04/2026
Royal Elementor Addons <= 1.7.1056 – Missing Authorization
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.1056. This makes it possible for unauthenticated attackers to perform an…
*-1.7.1056
1.7.1057
31/03/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 – Missing Authorization to Unauthenticated Custom Post Type Contents Exposure
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which…
*-1.7.1049
1.7.1050
16/03/2026
Royal Addons for Elementor <= 1.7.1049 – Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with…
*-1.7.1049
1.7.1050
10/03/2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 – Missing Authorization
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1052. This…
*-1.7.1052
1.7.1053
26/02/2026
Royal Elementor Addons and Templates <= 1.7.1036 – Missing Authorization to Unauthenticated Media File Upload
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized media file uploads due to a missing capability check on the 'wpr_addons_upload_file' AJAX endpoint in all versions up to,…
*-1.7.1036
1.7.1037
24/11/2025
Multiple Plugins and Themes <= (Various Versions) – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (
*-1.7.1031
1.7.1032
19/11/2025
Royal Elementor Addons and Templates <= 1.7.1036 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.7.1036
1.7.1037
18/11/2025
Royal Elementor Addons <= 1.7.1028 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.7.1028
1.7.1029
25/06/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.