Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Royal Elementor Addons — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Royal Elementor Addons, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with Royal Elementor Addons, a WordPress plugin developed by Royal Elementor, categorized under common weakness types such as Cross-Site Scripting and Broken Access Control. The aggregation focuses on known security flaws identified in this specific third-party extension used for enhancing page builder functionality, ensuring that users and administrators have access to accurate risk assessments regarding its codebase. This collection spans from early 2021 through the present day, capturing the evolution of security advisories and patches released by the vendor as new threats were discovered and addressed. Readers can utilize this resource to track the vendor's response to specific security incidents, understand the historical context of weakness classes prevalent in Elementor add-ons, and look up the product's vulnerability history to make informed decisions about updating or replacing the software. By consolidating these reports, the page aims to provide transparency into the security posture of Royal Elementor Addons, helping stakeholders evaluate the potential impact of unpatched vulnerabilities on their WordPress environments. This information is critical for maintaining the integrity of websites that rely on this plugin for dynamic content creation and design management.

Vendor: WP Royal

CVE IDTitleCVSSSeverityPublished
CVE-2026-25436 WordPress Royal Elementor Addons plugin < 1.7.1053 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-05-07
CVE-2026-27421 WordPress Royal Elementor Addons plugin < 1.7.1053 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-05-07
CVE-2026-40763 WordPress Royal Elementor Addons plugin <= 1.7.1056 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-04-15
CVE-2026-28135 WordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerability CWE-829 8.2 High2026-03-05
CVE-2025-39361 WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-05-07
CVE-2025-39543 WordPress Royal Elementor Addons plugin <= 1.3.977 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-04-16
CVE-2025-26990 WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability CWE-918 4.4 Medium2025-04-15
CVE-2024-56062 WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-12-31
CVE-2024-56226 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-12-31
CVE-2024-56227 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-12-31
CVE-2024-50442 WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability CWE-611 6.5 Medium2024-10-28
CVE-2024-44001 WordPress Royal Elementor Addons and Templates plugin <= 1.3.982 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-09-17
CVE-2024-32786 WordPress Royal Elementor Addons and Templates plugin <= 1.3.93 - IP Bypass vulnerability CWE-290 5.3 Medium2024-05-17
CVE-2024-31236 WordPress Royal Elementor Addons plugin <= 1.3.93 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-04-07

All 14 known CVE vulnerabilities affecting Royal Elementor Addons with full Chinese analysis, references, and POCs where available.