Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

WP Royal — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting WP Royal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WP Royal develops WordPress themes and plugins for website customization. Historically, their products have frequently contained vulnerabilities including remote code execution, cross-site scripting, and privilege escalation issues, with 15 CVEs documented to date. Security researchers have identified consistent patterns in their code quality, particularly in input validation and access control implementations. While no major public security incidents have been widely reported, the volume of disclosed vulnerabilities suggests ongoing challenges in secure development practices. Their products remain popular despite these concerns, indicating a tension between functionality and security that continues to affect their user base.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40763 WordPress Royal Elementor Addons plugin <= 1.7.1056 - Broken Access Control vulnerability — Royal Elementor AddonsCWE-862 5.3 Medium2026-04-15
CVE-2026-28135 WordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerability — Royal Elementor AddonsCWE-829 8.2 High2026-03-05
CVE-2025-39361 WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 6.5 Medium2025-05-07
CVE-2025-39543 WordPress Royal Elementor Addons plugin <= 1.3.977 - Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 6.5 Medium2025-04-16
CVE-2025-26990 WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability — Royal Elementor AddonsCWE-918 4.4 Medium2025-04-15
CVE-2024-56244 WordPress Ashe Extra plugin <= 1.2.92 - Broken Access Control vulnerability — Ashe ExtraCWE-862 5.4 Medium2025-01-02
CVE-2023-46079 WordPress Ashe Extra plugin <= 1.2.9 - Broken Access Control + CSRF vulnerability — Ashe ExtraCWE-862 5.4 Medium2025-01-02
CVE-2024-56062 WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 6.5 Medium2024-12-31
CVE-2024-56226 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Reflected Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 7.1 High2024-12-31
CVE-2024-56227 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Broken Access Control vulnerability — Royal Elementor AddonsCWE-862 4.3 Medium2024-12-31
CVE-2024-50442 WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability — Royal Elementor AddonsCWE-611 6.5 Medium2024-10-28
CVE-2024-44001 WordPress Royal Elementor Addons and Templates plugin <= 1.3.982 - Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 6.5 Medium2024-09-17
CVE-2024-32786 WordPress Royal Elementor Addons and Templates plugin <= 1.3.93 - IP Bypass vulnerability — Royal Elementor AddonsCWE-290 5.3 Medium2024-05-17
CVE-2024-32773 WordPress Royal Elementor Kit theme <= 1.0.116 - Cross Site Request Forgery (CSRF) vulnerability — Royal Elementor KitCWE-352 4.3 Medium2024-04-24
CVE-2024-31236 WordPress Royal Elementor Addons plugin <= 1.3.93 - Cross Site Scripting (XSS) vulnerability — Royal Elementor AddonsCWE-79 6.5 Medium2024-04-07

This page lists every published CVE security advisory associated with WP Royal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.