Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Royal Addons for Elementor – Addons and Templates Kit for Elementor — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in Royal Addons for Elementor – Addons and Templates Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Royal Addons for Elementor, a popular Elementor add-ons and templates kit, specifically focusing on the weakness class of Cross-Site Scripting (XSS). It collects disclosed security advisories and vulnerability records published between 2019 and 2024, covering various severity levels. Readers can track the vendor’s advisory history, analyze the specific weakness patterns within this product, and review the complete vulnerability timeline to understand the security posture of this WordPress plugin.

Vendor: wproyal

CVE ID Title CVSS Severity Published
CVE-2024-4087 Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget CWE-79 6.4 Medium 2024-06-01
CVE-2024-4342 Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-06-01
CVE-2024-3887 Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget CWE-79 5.4 Medium 2024-05-16
CVE-2024-1567 Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload CWE-434 8.2 High 2024-05-02
CVE-2024-3675 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes CWE-79 6.4 Medium 2024-05-02
CVE-2024-3889 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags CWE-79 6.4 Medium 2024-04-23
CVE-2024-2798 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-04-23
CVE-2024-2799 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags CWE-79 6.4 Medium 2024-04-23
CVE-2024-1500 Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget CWE-79 5.4 Medium 2024-03-07
CVE-2024-0516 Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta CWE-352 5.3 Medium 2024-02-20
CVE-2024-0512 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist CWE-352 4.3 Medium 2024-02-20
CVE-2024-0514 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare CWE-352 4.3 Medium 2024-02-20
CVE-2024-0515 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare CWE-352 4.3 Medium 2024-02-20
CVE-2024-0513 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist CWE-352 4.3 Medium 2024-02-20
CVE-2024-0442 Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-02-20
CVE-2024-0511 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta CWE-352 4.3 Medium 2024-02-08
CVE-2023-3709 Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure CWE-200 5.3 Medium 2023-07-18
CVE-2022-4707 Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation CWE-352 4.3 Medium 2023-01-10
CVE-2022-4701 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation CWE-285 4.3 Medium 2023-01-10
CVE-2022-4703 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion CWE-284 4.3 Medium 2023-01-10
CVE-2022-4705 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation CWE-284 4.3 Medium 2023-01-10
CVE-2022-4704 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import CWE-284 5.4 Medium 2023-01-10
CVE-2022-4710 Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting CWE-79 6.1 Medium 2023-01-10
CVE-2022-4708 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification CWE-284 4.3 Medium 2023-01-10
CVE-2022-4711 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update CWE-284 4.3 Medium 2023-01-10
CVE-2022-4702 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation CWE-284 5.4 Medium 2023-01-10
CVE-2022-4700 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation CWE-284 5.4 Medium 2023-01-10
CVE-2022-4709 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import CWE-284 4.3 Medium 2023-01-10

All 58 known CVE vulnerabilities affecting Royal Addons for Elementor – Addons and Templates Kit for Elementor with full Chinese analysis, references, and POCs where available.