Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 2
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
82 fiches
Royal Elementor Addons and Templates <= 1.7.1020 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and including, 1.7.1020 due to insufficient input sanitization and output escaping. This makes it…
*-1.7.1020
1.7.1021
30/05/2025
Royal Elementor Addons <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.7.1017
1.7.1018
07/05/2025
Royal Elementor Addons and Templates <= 1.7.1017 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This…
*-1.7.1017
1.7.1018
06/05/2025
Royal Elementor Addons <= 1.3.977 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.977 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.3.977
1.3.979
16/04/2025
Royal Elementor Addons <= 1.7.1006 – Authenticated (Admin+) Server Side Request Forgery
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.1006. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…
*-1.7.1006
1.7.1007
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping.…
*-1.7.1012
1.7.1013
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1012 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient input sanitization and output escaping. This makes…
*-1.7.1012
1.7.1013
11/04/2025
Royal Elementor Addons and Templates <= 1.7.1007 – Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or incorrect nonce validation on the 'wpr_filter_woo_products' function. This makes…
*-1.7.1007
1.7.1008
18/02/2025
Royal Elementor Addons and Templates <= 1.7.1006 – Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes…
*-1.7.1006
1.7.1007
13/01/2025
Royal Elementor Addons <= 1.7.1001 – Missing Authorization
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7.1001. This makes it possible for authenticated attackers,…
*-1.7.1001
1.7.1002
19/12/2024
Royal Elementor Addons <= 1.7.1001 – Reflected Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.7.1001
1.7.1002
19/12/2024
Royal Elementor Addons <= 1.3.987 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.987 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.3.987
1.7.1
18/12/2024
Royal Elementor Addons and Templates <= 1.7.1003 – Authenticated (Contributor+) Post Disclosure
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to insufficient restrictions on which posts can be included. This makes…
*-1.7.1003
1.7.1004
27/11/2024
Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on…
*-1.7.1001
1.7.1002
12/11/2024
Royal Elementor Addons and Templates <= 1.7.1001 – Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user…
*-1.7.1001
1.7.1002
12/11/2024
Royal Elementor Addons and Template <= 1.7.1001 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping. This makes…
*-1.7.1001
1.7.1002
12/11/2024
Royal Elementor Addons <= 1.3.980 – Authenticated (Author+) External Entity Injection
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to External Entity Injection in all versions up to, and including, 1.3.980. This is due to improper restriction and sanitization on external entities. This makes it possible…
*-1.3.980
1.3.981
24/10/2024
Royal Elementor Addons and Templates <= 1.3.986 – Authenticated (Subscriber+) Private Post Disclosure
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
*-1.3.986
1.3.987
16/10/2024
Royal Elementor Addons and Templates <= 1.3.986 – Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.986
1.3.987
07/10/2024
Royal Elementor Addons <= 1.3.982 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.3.982
1.3.985
29/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.