Royal Elementor Addons is a WordPress plugin ecosystem centered on page-builder extensions and design tooling, with a focused product line spanning the Royal Elementor Addons plugin and Royal Elementor Kit. Despite the narrow product scope, the vendor occupies a prominent position in the landscape due to the widespread deployment of WordPress plugins across web properties and the accessibility of plugin codebases to security researchers. The durable signal in this vendor's disclosures centers on web application and plugin-layer weakness classes; defenders should track this vendor's release cycles and treat plugin updates as part of routine WordPress site hardening. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Royal Elementor Addons over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5360CRITICAL The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files | Oct 31, 2023 | 9.8 | 91 | NO | YES |
CVE-2024-1567CRITICAL The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versi | May 2, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-32786CRITICAL Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93. | May 17, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-4701HIGH The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1. | Jan 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-4700HIGH The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3. | Jan 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-4704HIGH The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. | Jan 10, 2023 | 8.1 | 26 | NO | NO |
CVE-2022-4703HIGH The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59 | Jan 10, 2023 | 8.1 | 26 | NO | NO |
CVE-2025-1441HIGH The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. This is due to missing or | Feb 19, 2025 | 8.8 | 24 | NO | NO |
CVE-2022-47175HIGH Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions. | Oct 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-4708MEDIUM The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3 | Jan 10, 2023 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Royal Elementor Addons.
Media articles that mention a CVE ID that affects a product developed by Royal Elementor Addons — matched by CVE ID, not by vendor name.