Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 2
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
86 fiches
Royal Elementor Addons and Templates <= 1.7.1036 – Missing Authorization to Unauthenticated Media File Upload
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to unauthorized media file uploads due to a missing capability check on the 'wpr_addons_upload_file' AJAX endpoint in all versions up to,…
*-1.7.1036
1.7.1037
24/11/2025
Multiple Plugins and Themes <= (Various Versions) – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (
*-1.7.1031
1.7.1032
19/11/2025
Royal Elementor Addons and Templates <= 1.7.1036 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.7.1036
1.7.1037
18/11/2025
Royal Elementor Addons <= 1.7.1028 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1028 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.7.1028
1.7.1029
25/06/2025
Royal Elementor Addons and Templates <= 1.7.1020 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it…
*-1.7.1020
1.7.1021
30/05/2025
Royal Elementor Addons <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.7.1017
1.7.1018
07/05/2025
Royal Elementor Addons and Templates <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This…
*-1.7.1017
1.7.1018
06/05/2025
Royal Elementor Addons <= 1.3.977 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.977 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.3.977
1.3.979
16/04/2025
Royal Elementor Addons <= 1.7.1006 – Authenticated (Admin+) Server Side Request Forgery
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.1006. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…
*-1.7.1006
1.7.1007
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping.…
*-1.7.1012
1.7.1013
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes…
*-1.7.1012
1.7.1013
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1007 – Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes…
*-1.7.1007
1.7.1008
18/02/2025
Royal Elementor Addons and Templates <= 1.7.1006 – Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes…
*-1.7.1006
1.7.1007
13/01/2025
Royal Elementor Addons <= 1.7.1001 – Missing Authorization
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1001. This makes it possible for authenticated attackers,…
*-1.7.1001
1.7.1002
19/12/2024
Royal Elementor Addons <= 1.7.1001 – Reflected Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.7.1001
1.7.1002
19/12/2024
Royal Elementor Addons <= 1.3.987 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.987 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.3.987
1.7.1
18/12/2024
Royal Elementor Addons and Templates <= 1.7.1003 – Authenticated (Contributor+) Post Disclosure
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes…
*-1.7.1003
1.7.1004
27/11/2024
Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on…
*-1.7.1001
1.7.1002
12/11/2024
Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user…
*-1.7.1001
1.7.1002
12/11/2024
Royal Elementor Addons and Template <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes…
*-1.7.1001
1.7.1002
12/11/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.