Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Royal Addons for Elementor – Addons and Templates Kit for Elementor — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in Royal Addons for Elementor – Addons and Templates Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page tracks known security weaknesses associated with Royal Addons for Elementor, specifically categorized under the Royal theme vendor and tagged for WordPress plugin vulnerabilities. It aggregates a comprehensive collection of identified flaws affecting this specific Elementor addons and templates kit, covering reported incidents from its initial release up to the present day. The database includes issues ranging from cross-site scripting and SQL injection to unauthorized access and privilege escalation vulnerabilities that have been disclosed by security researchers, the vendor, or discovered during internal audits. By browsing this resource, users can efficiently track a vendor's security advisories to stay informed about patches and mitigation strategies. It also allows developers and administrators to understand the nature of a specific weakness class within the context of this popular page builder extension, seeing how theoretical vulnerabilities manifest in real-world implementations. Furthermore, visitors can look up a product's vulnerability history to assess the overall security posture of Royal Addons for Elementor over time, identifying patterns or recurring issues that may impact site stability or user data safety. This centralized view serves as a reference for security professionals evaluating third-party dependencies, helping them make informed decisions about upgrading or configuring their WordPress environments to minimize exposure to these documented risks without relying on marketing narratives or incomplete data points.

Vendor: wproyal

CVE IDTitleCVSSSeverityPublished
CVE-2024-4342 Royal Elementor Addons and Templates <= 1.3.975 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-06-01
CVE-2024-3887 Royal Elementor Addons and Templates <= 1.3.974 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget CWE-79 5.4 Medium2024-05-16
CVE-2024-1567 Royal Elementor Addons and Templates <= 1.3.94 - Unauthenticated Limited File Upload CWE-434 8.2 High2024-05-02
CVE-2024-3675 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes CWE-79 6.4 Medium2024-05-02
CVE-2024-3889 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags CWE-79 6.4 Medium2024-04-23
CVE-2024-2798 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CWE-79 6.4 Medium2024-04-23
CVE-2024-2799 Royal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags CWE-79 6.4 Medium2024-04-23
CVE-2024-1500 Royal Elementor Addons and Templates <= 1.3.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget CWE-79 5.4 Medium2024-03-07
CVE-2024-0516 Royal Elementor Addons and Templates <= 1.3.87 - Missing Authorization via wpr_update_form_action_meta CWE-352 5.3 Medium2024-02-20
CVE-2024-0512 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist CWE-352 4.3 Medium2024-02-20
CVE-2024-0514 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare CWE-352 4.3 Medium2024-02-20
CVE-2024-0515 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare CWE-352 4.3 Medium2024-02-20
CVE-2024-0513 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist CWE-352 4.3 Medium2024-02-20
CVE-2024-0442 Royal Elementor Addons and Templates <= 1.3.87 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-02-20
CVE-2024-0511 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta CWE-352 4.3 Medium2024-02-08
CVE-2023-3709 Royal Elementor Addons <=1.3.70 - Unauthenticated MailChimp API Key Disclosure CWE-200 5.3 Medium2023-07-18
CVE-2022-4707 Royal Elementor Addons <= 1.3.59 - Cross-Site Request Forgery to Menu Template creation CWE-352 4.3 Medium2023-01-10
CVE-2022-4701 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Activation CWE-285 4.3 Medium2023-01-10
CVE-2022-4703 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Import Deletion CWE-284 4.3 Medium2023-01-10
CVE-2022-4705 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Activation CWE-284 4.3 Medium2023-01-10
CVE-2022-4704 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Import CWE-284 5.4 Medium2023-01-10
CVE-2022-4710 Royal Elementor Addons <= 1.3.59 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2023-01-10
CVE-2022-4708 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Conditions Modification CWE-284 4.3 Medium2023-01-10
CVE-2022-4711 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Menu Settings Update CWE-284 4.3 Medium2023-01-10
CVE-2022-4702 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Plugin Deactivation CWE-284 5.4 Medium2023-01-10
CVE-2022-4700 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Theme Activation CWE-284 5.4 Medium2023-01-10
CVE-2022-4709 Royal Elementor Addons <= 1.3.59 - Insufficient Access Control to Template Kit Import CWE-284 4.3 Medium2023-01-10

All 57 known CVE vulnerabilities affecting Royal Addons for Elementor – Addons and Templates Kit for Elementor with full Chinese analysis, references, and POCs where available.