Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Royal — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting WP Royal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WP Royal develops WordPress themes and plugins for website customization. Historically, their products have frequently contained vulnerabilities including remote code execution, cross-site scripting, and privilege escalation issues, with 15 CVEs documented to date. Security researchers have identified consistent patterns in their code quality, particularly in input validation and access control implementations. While no major public security incidents have been widely reported, the volume of disclosed vulnerabilities suggests ongoing challenges in secure development practices. Their products remain popular despite these concerns, indicating a tension between functionality and security that continues to affect their user base.

CVE ID Title CVSS Severity Published
CVE-2026-40763 WordPress Royal Elementor Addons plugin <= 1.7.1056 - Broken Access Control vulnerability — Royal Elementor Addons CWE-862 5.3 Medium 2026-04-15
CVE-2026-28135 WordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerability — Royal Elementor Addons CWE-829 8.2 High 2026-03-05
CVE-2025-39361 WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 6.5 Medium 2025-05-07
CVE-2025-39543 WordPress Royal Elementor Addons plugin <= 1.3.977 - Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 6.5 Medium 2025-04-16
CVE-2025-26990 WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability — Royal Elementor Addons CWE-918 4.4 Medium 2025-04-15
CVE-2024-56244 WordPress Ashe Extra plugin <= 1.2.92 - Broken Access Control vulnerability — Ashe Extra CWE-862 5.4 Medium 2025-01-02
CVE-2023-46079 WordPress Ashe Extra plugin <= 1.2.9 - Broken Access Control + CSRF vulnerability — Ashe Extra CWE-862 5.4 Medium 2025-01-02
CVE-2024-56062 WordPress Royal Elementor Addons and Templates plugin <= 1.3.987 - Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 6.5 Medium 2024-12-31
CVE-2024-56226 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Reflected Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 7.1 High 2024-12-31
CVE-2024-56227 WordPress Royal Elementor Addons plugin <= 1.7.1001 - Broken Access Control vulnerability — Royal Elementor Addons CWE-862 4.3 Medium 2024-12-31
CVE-2024-50442 WordPress Royal Elementor Addons and Templates plugin <= 1.3.980 - XML External Entity (XXE) vulnerability — Royal Elementor Addons CWE-611 6.5 Medium 2024-10-28
CVE-2024-44001 WordPress Royal Elementor Addons and Templates plugin <= 1.3.982 - Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 6.5 Medium 2024-09-17
CVE-2024-32786 WordPress Royal Elementor Addons and Templates plugin <= 1.3.93 - IP Bypass vulnerability — Royal Elementor Addons CWE-290 5.3 Medium 2024-05-17
CVE-2024-32773 WordPress Royal Elementor Kit theme <= 1.0.116 - Cross Site Request Forgery (CSRF) vulnerability — Royal Elementor Kit CWE-352 4.3 Medium 2024-04-24
CVE-2024-31236 WordPress Royal Elementor Addons plugin <= 1.3.93 - Cross Site Scripting (XSS) vulnerability — Royal Elementor Addons CWE-79 6.5 Medium 2024-04-07

This page lists every published CVE security advisory associated with WP Royal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.