Known Vulnerabilities for Royal Elementor Addons Pro by Royal Elementor Addons
Listed below are 8 of the newest known vulnerabilities associated with "Royal Elementor Addons Pro" by "Royal Elementor Addons".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40720 json | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-19217 json | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-17123 json | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including... | Not Provided | 2026-08-16 | 2026-08-17 |
| CVE-2026-13405 json | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writ... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-13402 json | The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the template... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-8118 json | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary Fil... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2026-6229 json | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including... | Not Provided | 2026-05-02 | 2026-08-17 |
| CVE-2026-5428 json | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image ... | Not Provided | 2026-04-24 | 2026-08-14 |