Extension WordPress
Vulnérabilités Royal Addons for Elementor – Addons and Templates Kit for Elementor, page 3
Cette page rassemble les failles publiées pour Royal Addons for Elementor – Addons and Templates Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Royal Addons for Elementor – Addons and Templates Kit for Elementor
82 fiches
Royal Elementor Addons and Templates <= 1.3.980 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping…
*-1.3.980
1.3.981
23/07/2024
Royal Elementor Addons and Templates <= 1.3.976 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list’ parameter in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.3.976
1.3.977
06/06/2024
Royal Elementor Addons and Templates <= 1.3.976 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 1.3.976 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.3.976
1.3.977
06/06/2024
Royal Elementor Addons and Templates <= 1.3.975 – Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Back to Top widget in all versions up to, and including, 1.3.975 due to insufficient input sanitization and output escaping…
*-1.3.975
1.3.976
31/05/2024
Royal Elementor Addons and Templates <= 1.3.975 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image hotspot, image accordion, off canvas, woogrid, and product mini cart widgets in all versions up to, and including, 1.3.975…
*-1.3.975
1.3.976
31/05/2024
Royal Elementor Addons and Templates <= 1.3.974 – Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user…
*-1.3.974
1.3.975
15/05/2024
Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user…
*-1.3.971
1.3.972
22/04/2024
Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flip Carousel, Flip Box, Post Grid, and Taxonomy List widgets in all versions up to, and including, 1.3.971 due to…
*-1.3.971
1.3.972
22/04/2024
Royal Elementor Addons <= 1.3.93 – Unauthenticated IP Spoofing
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.3.93 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof…
*-1.3.93
1.3.95
22/04/2024
Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on…
*-1.3.971
1.3.972
22/04/2024
Royal Elementor Addons and Templates <= 1.3.971 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization…
*-1.3.971
1.3.972
22/04/2024
Royal Elementor Addons and Templates <= 1.3.94 – Unauthenticated Limited File Upload
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for…
*-1.3.94
1.3.95
19/04/2024
Royal Elementor Addons <= 1.3.93 – Authenticated (Contributor+) Stored Cross-Site Scriting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-1.3.93
1.3.95
05/04/2024
Royal Elementor Addons and Templates <= 1.3.91 – Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied…
*-1.3.91
1.3.92
06/03/2024
Royal Elementor Addons and Templates <= 1.3.87 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via element URL parameters in all versions up to, and including, 1.3.87 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.87
1.3.88
08/02/2024
Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via wpr_update_form_action_meta
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes…
*-1.3.87
1.3.88
07/02/2024
Royal Elementor Addons and Templates <= 1.3.87 – Missing Authorization via wpr_update_form_action_meta
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible…
*-1.3.87
1.3.88
07/02/2024
Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via add_to_wishlist
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_wishlist function. This makes…
*-1.3.87
1.3.88
07/02/2024
Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via add_to_compare
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the add_to_compare function. This makes…
*-1.3.87
1.3.88
07/02/2024
Royal Elementor Addons and Templates <= 1.3.87 – Cross-Site Request Forgery via remove_from_compare
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes…
*-1.3.87
1.3.88
07/02/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.