Pricing
Case studies
Login
Start trial
Royal Elementor Addons
WP Royal
Developer
1.7.1053
Latest version
600,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
67 patched
19 Mitigation rules
WordPress Royal Addons for Elementor - Addons and Templates Kit for Elementor plugin <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure vulnerability
<= 1.7.1049
18/03/2026
Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass vulnerability
<= 1.7.1049
11/03/2026
Other vulnerability Type vulnerability
<= 1.7.1052
26/02/2026
Missing Authorization via wpr_update_form_action_meta vulnerability
<= 1.3.87
03/02/2026
Cross-Site Request Forgery via add_to_compare vulnerability
<= 1.3.87
03/02/2026
Cross-Site Request Forgery via remove_from_compare vulnerability
<= 1.3.87
03/02/2026
Cross-Site Request Forgery via remove_from_wishlist vulnerability
<= 1.3.87
03/02/2026
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 1.3.971
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags vulnerability
<= 1.3.971
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags vulnerability
<= 1.3.971
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget vulnerability
<= 1.3.975
02/02/2026
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget vulnerability
<= 1.7.1001
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget vulnerability
<= 1.7.1001
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1012
31/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1017
31/12/2025
Missing Authorization to Unauthenticated Media File Upload vulnerability
<= 1.7.1036
19/12/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
<= 1.7.1031
20/11/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1036
18/11/2025
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets vulnerability
<= 1.7.1024
26/06/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1020
30/05/2025
Cross Site Scripting (XSS) vulnerability
<= 1.7.1017
07/05/2025
Cross Site Scripting (XSS) vulnerability
<= 1.3.977
16/04/2025
Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1012
11/04/2025
Server Side Request Forgery (SSRF) vulnerability
<= 1.7.1006
11/04/2025
Cross-Site Request Forgery to Reflected Cross-Site Scripting vulnerability
<= 1.7.1007
18/02/2025
Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
<= 1.7.1006
13/01/2025
Broken Access Control vulnerability
<= 1.7.1001
19/12/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.7.1001
19/12/2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.987
18/12/2024
Authenticated (Contributor+) Post Disclosure vulnerability
<= 1.7.1003
27/11/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget vulnerability
<= 1.7.1001
26/11/2024
XML External Entity (XXE) vulnerability
<= 1.3.980
24/10/2024
Authenticated (Subscriber+) Private Post Disclosure vulnerability
<= 1.3.986
16/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget vulnerability
<= 1.3.986
08/10/2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.982
29/08/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget vulnerability
<= 1.3.980
24/07/2024
Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads vulnerability
<= 1.3.976
07/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.976
07/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.975
03/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget vulnerability
<= 1.3.974
16/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes vulnerability
<= 1.3.971
23/04/2024
IP Bypass vulnerability
<= 1.3.93
22/04/2024
Unauthenticated Limited File Upload vulnerability
<= 1.3.94
22/04/2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.93
05/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget vulnerability
<= 1.3.91
07/03/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.87
12/02/2024
Multiple Cross-Site Request Forgery vulnerability
<= 1.3.87
08/02/2024
Missing Authorization & Cross-Site Request Forgery via wpr_update_form_action_meta vulnerability
<= 1.3.87
08/02/2024
Unauthenticated Arbitrary Post Read vulnerability
< 1.3.81
08/02/2024
Unauthenticated Arbitrary File Upload vulnerability
<= 1.3.78
14/10/2023
Multiple Cross Site Request Forgery (CSRF)
<= 1.3.75
22/08/2023
Reflected Cross Site Scripting (XSS) vulnerability
< 1.3.71
18/07/2023
Unauthenticated MailChimp API Key Disclosure vulnerability
<= 1.3.70
18/07/2023
Insufficient Access Control to Template Kit Import Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Theme Activation Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Plugin Deactivation Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Menu Settings Update Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Template Conditions Modification Vulnerability
<= 1.3.59
10/01/2023
Reflected Cross-Site Scripting Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Template Import Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Import Deletion Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Plugin Activation Vulnerability
<= 1.3.59
10/01/2023
Cross-Site Request Forgery to Menu Template creation Vulnerability
<= 1.3.59
10/01/2023
Insufficient Access Control to Template Activation Vulnerability
<= 1.3.59
10/01/2023
Subscriber+ Arbitrary Post Deletion vulnerability
< 1.3.56
20/12/2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
<= 1.3.32
28/02/2022
Sensitive Information Disclosure vulnerability
<= 1.3.32
28/02/2022