Elementor 的 Royal Addons 插件在 1.7.1066 版本之前,在将自定义小部件的标记写入后续会被执行的文件时,未能正确对其进行 sanitization(净化/过滤)处理。这使得具备 manage_options 权限的用户(在 WordPress 多站点环境下,还包括那些本身不具备代码执行权限的非超级管理员子站点管理员)能够执行任意 PHP 代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Royal Addons for Elementor | < 1.7.1066 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Royal Addons for Elementor | 0 ~ 1.7.1066 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75860 | JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update | |
| CVE-2026-74992 | Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload | |
| CVE-2026-19699 | GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure | |
| CVE-2026-19615 | Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC | |
| CVE-2026-19697 | GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload | |
| CVE-2026-15049 | Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import |
No comments yet