Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Royal Addons for Elementor – Addons and Templates Kit for Elementor — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in Royal Addons for Elementor – Addons and Templates Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page tracks known security vulnerabilities associated with Royal Addons for Elementor, a plugin and templates kit designed for the Elementor page builder. It serves as a centralized resource for identifying weaknesses such as cross-site scripting, authorization flaws, and data exposure issues within this specific software ecosystem. The collection covers reported security incidents and patch releases ranging from the plugin’s initial launch through its most recent updates. This historical view allows users to see how the product’s security posture has evolved over time and which areas have historically been targeted by attackers. By aggregating this data, the page provides a clear timeline of exposure and remediation efforts. Visitors can use this resource to track vendor advisories and monitor the status of ongoing security issues related to Royal Addons. It helps in understanding the specific weakness classes that affect this tool, such as input validation errors or insecure direct object references. Furthermore, users can look up a product's vulnerability history to assess risk levels before installation or after an update. This transparency supports better decision-making for developers and site administrators who rely on Elementor and its add-ons. The information is compiled from public security reports, developer disclosures, and community findings to ensure accuracy. Understanding these patterns is crucial for maintaining the integrity of WordPress sites that depend on third-party extensions. This page does not provide workarounds or fixes but rather documents the existence and resolution of threats.

Vendor: wproyal

CVE IDTitleCVSSSeverityPublished
CVE-2026-6504 Royal Addons for Elementor <= 1.7.1058 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter CWE-79 6.4 Medium2026-05-14
CVE-2026-5159 Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter CWE-79 6.4 Medium2026-05-05
CVE-2026-4803 Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta CWE-79 7.2 High2026-05-05
CVE-2026-4024 Royal Addons for Elementor <= 1.7.1056 - Missing Authorization to Unauthenticated Form Action Meta Modification CWE-862 5.3 Medium2026-05-02
CVE-2026-6229 Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter CWE-918 7.2 High2026-05-02
CVE-2026-5428 Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field CWE-79 6.4 Medium2026-04-24
CVE-2026-5162 Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget CWE-79 6.4 Medium2026-04-17
CVE-2026-0664 Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass CWE-79 6.4 Medium2026-04-04
CVE-2026-2373 Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure CWE-862 5.3 Medium2026-03-17
CVE-2025-13067 Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass CWE-434 8.8 High2026-03-11
CVE-2025-6251 Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-11-19
CVE-2025-5338 Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets CWE-79 6.4 Medium2025-06-26
CVE-2025-3813 Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-05-31
CVE-2024-12120 Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 5.4 Medium2025-05-07
CVE-2025-1456 Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-04-12
CVE-2025-1455 Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2025-04-12
CVE-2025-1441 Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting CWE-352 6.1 Medium2025-02-19
CVE-2025-0393 Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting CWE-352 6.1 Medium2025-01-14
CVE-2024-10798 Royal Elementor Addons and Templates <= 1.7.1003 - Authenticated (Contributor+) Post Disclosure CWE-639 4.3 Medium2024-11-28
CVE-2024-9682 Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget CWE-79 6.4 Medium2024-11-13
CVE-2024-9668 Royal Elementor Addons and Templates <= 1.7.1001 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget CWE-79 6.4 Medium2024-11-13
CVE-2024-9059 Royal Elementor Addons and Template <= 1.7.1001 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget CWE-79 6.4 Medium2024-11-13
CVE-2024-7417 Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosure CWE-200 4.3 Medium2024-10-17
CVE-2024-8482 Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget CWE-79 6.4 Medium2024-10-08
CVE-2024-5818 Royal Elementor Addons and Templates <= 1.3.980 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget CWE-79 6.4 Medium2024-07-24
CVE-2024-4488 Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-06-07
CVE-2024-4489 Royal Elementor Addons and Templates <= 1.3.976 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads CWE-79 6.4 Medium2024-06-07
CVE-2024-4087 Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget CWE-79 6.4 Medium2024-06-01
CVE-2024-4342 Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-06-01
CVE-2024-3887 Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget CWE-79 5.4 Medium2024-05-16

All 55 known CVE vulnerabilities affecting Royal Addons for Elementor – Addons and Templates Kit for Elementor with full Chinese analysis, references, and POCs where available.