Royal Addons for Elementor – Addons and Templates Kit for Elementor

Information

Software Type Plugin
Software Slug royal-elementor-addons (view on wordpress.org)
Software Status Active
Software Author wproyal
Software Website royal-elementor-addons.com
Software Downloads 19,302,964
Software Active Installs 600,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 82 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source Patched CVE-2026-8118 6.5 Jack Taylor June 18, 2026
Royal Addons for Elementor <= 1.7.1058 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter Patched CVE-2026-6504 6.4 Romain Deperne (ang3L) May 13, 2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2026-27421 6.4 Peter Thaleikis May 7, 2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1053 - Missing Authorization Patched CVE-2026-25436 5.3 Bao - BlueRock May 7, 2026
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Follow Button Text' Parameter Patched CVE-2026-5159 6.4 Caspian May 4, 2026
Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta Patched CVE-2026-4803 7.2 andrea bocchetti May 4, 2026
Royal Addons for Elementor <= 1.7.1056 - Missing Authorization to Unauthenticated Form Action Meta Modification Patched CVE-2026-4024 5.3 Nguyen C May 1, 2026
Royal Addons for Elementor <= 1.7.1057 - Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter Patched CVE-2026-6229 7.2 Dmitrii Ignatyev May 1, 2026
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field Patched CVE-2026-5428 6.4 Dmitrii Ignatyev April 23, 2026
Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget Patched CVE-2026-5162 6.4 Caspian April 16, 2026
Royal Elementor Addons < 1.7.1041 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-40720 7.2 Drew Webber (mcdruid) April 16, 2026
Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass Patched CVE-2026-0664 6.4 iwd - Prysm Sec April 3, 2026
Royal Elementor Addons <= 1.7.1056 - Missing Authorization Patched CVE-2026-40763 5.3 Bao - BlueRock March 31, 2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure Patched CVE-2026-2373 5.3 Quốc Huy (jtwings) March 16, 2026
Royal Addons for Elementor <= 1.7.1049 - Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass Patched CVE-2025-13067 8.8 mikemyers March 10, 2026
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1052 - Missing Authorization Patched CVE-2026-28135 5.3 Drew Webber (mcdruid) February 26, 2026
Royal Elementor Addons and Templates <= 1.7.1036 - Missing Authorization to Unauthenticated Media File Upload Patched CVE-2025-11363 5.3 Envel Le Clainche November 24, 2025
Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library Patched CVE-2025-5092 6.4 Webbernaut November 19, 2025
Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-6251 6.4 stealthcopter November 18, 2025
Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets Patched CVE-2025-5338 6.4 Asaf Mozes June 25, 2025

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation