VendorsRoyal Elementor Addonsroyal_elementor_addonsany version
Vulnerabilities

Royal Elementor Addons Royal Elementor Addons any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

58CVEs
CVE-2023-5360
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
Published 2023-10-31 · Modified
9.81 PoCEPSS 0.817
CVE-2024-1567
Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload
Published 2024-05-02 · Modified
9.8EPSS 0.011
CVE-2024-32786
WordPress Royal Elementor Addons and Templates plugin <= 1.3.93 - IP Bypass vulnerability
Published 2024-05-17 · Analyzed
9.8EPSS 0.005
CVE-2022-4700
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation
Published 2023-01-10 · Modified
8.8EPSS 0.008
CVE-2022-4701
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation
Published 2023-01-10 · Modified
8.8EPSS 0.007
CVE-2022-47175
WordPress Royal Elementor Addons Plugin <= 1.3.75 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-10-06 · Modified
8.8EPSS 0.003
CVE-2025-1441
Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
Published 2025-02-19 · Analyzed
8.8EPSS 0.002
CVE-2022-4703
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion
Published 2023-01-10 · Modified
8.1EPSS 0.009
CVE-2022-4704
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import
Published 2023-01-10 · Modified
8.1EPSS 0.008
CVE-2023-5922
Royal Elementor Addons and Templates < 1.3.81 - Unauthenticated Arbitrary Post Read
Published 2024-01-16 · Modified
7.5EPSS 0.007
CVE-2024-50442
WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability
Published 2024-10-28 · Modified
7.2EPSS 0.005
CVE-2024-56226
WordPress Royal Elementor Addons plugin <= 1.7.1001 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-12-31 · Modified
7.1EPSS 0.003
CVE-2022-4702
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation
Published 2023-01-10 · Modified
6.5EPSS 0.008
CVE-2022-4708
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification
Published 2023-01-10 · Modified
6.5EPSS 0.006
CVE-2022-4709
Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import
Published 2023-01-10 · Modified
6.5EPSS 0.006
CVE-2024-31236
WordPress Royal Elementor Addons plugin <= 1.3.93 - Cross Site Scripting (XSS) vulnerability
Published 2024-04-07 · Modified
6.5EPSS 0.004
CVE-2022-4707
Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation
Published 2023-01-10 · Modified
6.5EPSS 0.003
CVE-2024-44001
WordPress Royal Elementor Addons and Templates plugin <= 1.3.982 - Cross Site Scripting (XSS) vulnerability
Published 2024-09-17 · Modified
6.5EPSS 0.003
CVE-2024-56062
WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability
Published 2024-12-31 · Modified
6.5EPSS 0.002
CVE-2025-39361
WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability
Published 2025-05-07 · Modified
6.5EPSS 0.002
CVE-2024-3675
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes
Published 2024-05-02 · Modified
6.4EPSS 0.006
CVE-2024-0442
Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-02-20 · Modified
6.4EPSS 0.005
CVE-2024-8482
Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget
Published 2024-10-08 · Analyzed
6.4EPSS 0.004
CVE-2024-2799
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
Published 2024-04-23 · Modified
6.4EPSS 0.004
CVE-2024-9682
Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget
Published 2024-11-13 · Analyzed
6.4EPSS 0.004
CVE-2024-9668
Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
Published 2024-11-13 · Analyzed
6.4EPSS 0.004
CVE-2024-9059
Royal Elementor Addons and Template <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget
Published 2024-11-13 · Analyzed
6.4EPSS 0.004
CVE-2024-4342
Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-01 · Modified
6.4EPSS 0.003
CVE-2024-3889
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags
Published 2024-04-23 · Modified
6.4EPSS 0.003
CVE-2024-2798
Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Published 2024-04-23 · Modified
6.4EPSS 0.003
CVE-2024-4087
Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget
Published 2024-06-01 · Modified
6.4EPSS 0.003
CVE-2024-4488
Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-07 · Modified
6.4EPSS 0.003
CVE-2024-4489
Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads
Published 2024-06-07 · Modified
6.4EPSS 0.003
CVE-2025-1455
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-04-12 · Analyzed
6.4EPSS 0.003
CVE-2025-1456
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting
Published 2025-04-12 · Analyzed
6.4EPSS 0.003
CVE-2024-5818
Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget
Published 2024-07-24 · Modified
6.4EPSS 0.003
CVE-2025-3813
Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2025-05-31 · Analyzed
6.4EPSS 0.002
CVE-2025-5338
Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
Published 2025-06-26 · Modified
6.4EPSS 0.002
CVE-2022-4710
Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting
Published 2023-01-10 · Modified
6.1EPSS 0.007
CVE-2025-0393
Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
Published 2025-01-14 · Analyzed
6.1EPSS 0.002
1 / 2Next →