Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Royal Addons for Elementor – Addons and Templates Kit for Elementor — Vulnerabilities & Security Advisories 55

All 55 CVE vulnerabilities found in Royal Addons for Elementor – Addons and Templates Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page tracks known security vulnerabilities associated with Royal Addons for Elementor, a plugin and templates kit designed for the Elementor page builder. It serves as a centralized resource for identifying weaknesses such as cross-site scripting, authorization flaws, and data exposure issues within this specific software ecosystem. The collection covers reported security incidents and patch releases ranging from the plugin’s initial launch through its most recent updates. This historical view allows users to see how the product’s security posture has evolved over time and which areas have historically been targeted by attackers. By aggregating this data, the page provides a clear timeline of exposure and remediation efforts. Visitors can use this resource to track vendor advisories and monitor the status of ongoing security issues related to Royal Addons. It helps in understanding the specific weakness classes that affect this tool, such as input validation errors or insecure direct object references. Furthermore, users can look up a product's vulnerability history to assess risk levels before installation or after an update. This transparency supports better decision-making for developers and site administrators who rely on Elementor and its add-ons. The information is compiled from public security reports, developer disclosures, and community findings to ensure accuracy. Understanding these patterns is crucial for maintaining the integrity of WordPress sites that depend on third-party extensions. This page does not provide workarounds or fixes but rather documents the existence and resolution of threats.

Vendor: wproyal

CVE IDTitleCVSSSeverityPublished
CVE-2024-1567 Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload CWE-434 8.2 High2024-05-02
CVE-2024-3675 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes CWE-79 6.4 Medium2024-05-02
CVE-2024-3889 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags CWE-79 6.4 Medium2024-04-23
CVE-2024-2798 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CWE-79 6.4 Medium2024-04-23
CVE-2024-2799 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags CWE-79 6.4 Medium2024-04-23
CVE-2024-1500 Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget CWE-79 5.4 Medium2024-03-07
CVE-2024-0516 Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta CWE-352 5.3 Medium2024-02-20
CVE-2024-0512 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist CWE-352 4.3 Medium2024-02-20
CVE-2024-0514 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare CWE-352 4.3 Medium2024-02-20
CVE-2024-0515 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare CWE-352 4.3 Medium2024-02-20
CVE-2024-0513 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist CWE-352 4.3 Medium2024-02-20
CVE-2024-0442 Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0511 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta CWE-352 4.3 Medium2024-02-08
CVE-2023-3709 Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure CWE-200 5.3 Medium2023-07-18
CVE-2022-4707 Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation CWE-352 4.3 Medium2023-01-10
CVE-2022-4701 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation CWE-285 4.3 Medium2023-01-10
CVE-2022-4703 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion CWE-284 4.3 Medium2023-01-10
CVE-2022-4705 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation CWE-284 4.3 Medium2023-01-10
CVE-2022-4704 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import CWE-284 5.4 Medium2023-01-10
CVE-2022-4710 Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2023-01-10
CVE-2022-4708 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification CWE-284 4.3 Medium2023-01-10
CVE-2022-4711 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update CWE-284 4.3 Medium2023-01-10
CVE-2022-4702 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation CWE-284 5.4 Medium2023-01-10
CVE-2022-4700 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation CWE-284 5.4 Medium2023-01-10
CVE-2022-4709 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import CWE-284 4.3 Medium2023-01-10

All 55 known CVE vulnerabilities affecting Royal Addons for Elementor – Addons and Templates Kit for Elementor with full Chinese analysis, references, and POCs where available.