Extension WordPress

Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 2

Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

82Vulnérabilités
1Critiques
82Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor

82 fiches

CVE-2025-3813 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1020 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.7.1020

Correctif

1.7.1021

Publication

30/05/2025

CVE-2025-39361 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-1.7.1017

Correctif

1.7.1018

Publication

07/05/2025

CVE-2024-12120 Moyenne · 5,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.7.1017

Correctif

1.7.1018

Publication

06/05/2025

CVE-2025-39543 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.977 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.977 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-1.3.977

Correctif

1.3.979

Publication

16/04/2025

CVE-2025-26990 Moyenne · 5,5
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1006 – Authenticated (Admin+) Server Side Request Forgery

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.1006. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…

Versions affectées

*-1.7.1006

Correctif

1.7.1007

Publication

11/04/2025

CVE-2025-1456 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.7.1012

Correctif

1.7.1013

Publication

11/04/2025

CVE-2025-1455 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.7.1012

Correctif

1.7.1013

Publication

11/04/2025

CVE-2025-1441 Moyenne · 6,1
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1007 – Cross-Site Request Forgery to Reflected Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes…

Versions affectées

*-1.7.1007

Correctif

1.7.1008

Publication

18/02/2025

CVE-2025-0393 Moyenne · 6,1
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1006 – Cross-Site Request Forgery to Reflected Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes…

Versions affectées

*-1.7.1006

Correctif

1.7.1007

Publication

13/01/2025

CVE-2024-56227 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1001 – Missing Authorization

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1001. This makes it possible for authenticated attackers,…

Versions affectées

*-1.7.1001

Correctif

1.7.1002

Publication

19/12/2024

CVE-2024-56226 Moyenne · 6,1
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.7.1001 – Reflected Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-1.7.1001

Correctif

1.7.1002

Publication

19/12/2024

CVE-2024-56062 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.987 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.987 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-1.3.987

Correctif

1.7.1

Publication

18/12/2024

CVE-2024-10798 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1003 – Authenticated (Contributor+) Post Disclosure

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes…

Versions affectées

*-1.7.1003

Correctif

1.7.1004

Publication

27/11/2024

CVE-2024-9682 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on…

Versions affectées

*-1.7.1001

Correctif

1.7.1002

Publication

12/11/2024

CVE-2024-9668 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-1.7.1001

Correctif

1.7.1002

Publication

12/11/2024

CVE-2024-9059 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Template <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.7.1001

Correctif

1.7.1002

Publication

12/11/2024

CVE-2024-50442 Moyenne · 5,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.980 – Authenticated (Author+) External Entity Injection

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions up to, and including, 1.3.980. This is due to improper restriction and sanitization on external entities. This makes it possible…

Versions affectées

*-1.3.980

Correctif

1.3.981

Publication

24/10/2024

CVE-2024-7417 Moyenne · 4,3
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.986 – Authenticated (Subscriber+) Private Post Disclosure

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

Versions affectées

*-1.3.986

Correctif

1.3.987

Publication

16/10/2024

CVE-2024-8482 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons and Templates <= 1.3.986 – Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.3.986

Correctif

1.3.987

Publication

07/10/2024

CVE-2024-44001 Moyenne · 6,4
Royal Addons for Elementor – Addons and Templates Kit for Elementor

Royal Elementor Addons <= 1.3.982 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-1.3.982

Correctif

1.3.985

Publication

29/08/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités