Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Royal Elementor Addons
WP Royal
Developer
1.7.1039
Latest version
600,000
Installations
4 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
49 fixed
18 Mitigation rules
Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets vulnerability
<= 1.7.1024
Jun 26, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1020
May 30, 2025
Cross Site Scripting (XSS) vulnerability
<= 1.7.1017
May 7, 2025
Cross Site Scripting (XSS) vulnerability
<= 1.3.977
Apr 16, 2025
Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.7.1012
Apr 11, 2025
Server Side Request Forgery (SSRF) vulnerability
<= 1.7.1006
Apr 11, 2025
Cross-Site Request Forgery to Reflected Cross-Site Scripting vulnerability
<= 1.7.1007
Feb 18, 2025
Cross-Site Request Forgery to Stored Cross-Site Scripting vulnerability
<= 1.7.1006
Jan 13, 2025
Broken Access Control vulnerability
<= 1.7.1001
Dec 19, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.7.1001
Dec 19, 2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.987
Dec 18, 2024
Authenticated (Contributor+) Post Disclosure vulnerability
<= 1.7.1003
Nov 27, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget vulnerability
<= 1.7.1001
Nov 26, 2024
XML External Entity (XXE) vulnerability
<= 1.3.980
Oct 24, 2024
Authenticated (Subscriber+) Private Post Disclosure vulnerability
<= 1.3.986
Oct 16, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget vulnerability
<= 1.3.986
Oct 8, 2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.982
Aug 29, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget vulnerability
<= 1.3.980
Jul 24, 2024
Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads vulnerability
<= 1.3.976
Jun 7, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.976
Jun 7, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.975
Jun 3, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget vulnerability
<= 1.3.974
May 16, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes vulnerability
<= 1.3.971
Apr 23, 2024
IP Bypass vulnerability
<= 1.3.93
Apr 22, 2024
Unauthenticated Limited File Upload vulnerability
<= 1.3.94
Apr 22, 2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.93
Apr 5, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget vulnerability
<= 1.3.91
Mar 7, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.87
Feb 12, 2024
Multiple Cross-Site Request Forgery vulnerability
<= 1.3.87
Feb 8, 2024
Missing Authorization & Cross-Site Request Forgery via wpr_update_form_action_meta vulnerability
<= 1.3.87
Feb 8, 2024
Unauthenticated Arbitrary Post Read vulnerability
< 1.3.81
Feb 8, 2024
Unauthenticated Arbitrary File Upload vulnerability
<= 1.3.78
Oct 14, 2023
Multiple Cross Site Request Forgery (CSRF)
<= 1.3.75
Aug 22, 2023
Reflected Cross Site Scripting (XSS) vulnerability
< 1.3.71
Jul 18, 2023
Unauthenticated MailChimp API Key Disclosure vulnerability
<= 1.3.70
Jul 18, 2023
Insufficient Access Control to Template Kit Import Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Theme Activation Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Plugin Deactivation Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Menu Settings Update Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Template Conditions Modification Vulnerability
<= 1.3.59
Jan 10, 2023
Reflected Cross-Site Scripting Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Template Import Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Import Deletion Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Plugin Activation Vulnerability
<= 1.3.59
Jan 10, 2023
Cross-Site Request Forgery to Menu Template creation Vulnerability
<= 1.3.59
Jan 10, 2023
Insufficient Access Control to Template Activation Vulnerability
<= 1.3.59
Jan 10, 2023
Subscriber+ Arbitrary Post Deletion vulnerability
< 1.3.56
Dec 20, 2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
<= 1.3.32
Feb 28, 2022
Sensitive Information Disclosure vulnerability
<= 1.3.32
Feb 28, 2022