WordPress Plugin Vulnerabilities
Royal Elementor Addons and Templates < 1.7.1037 - Unauthenticated Media File Upload
Description
The plugin does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Envel Le Clainche
Submitter
Envel Le Clainche
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2025-11-24 (about 1 month ago)
Added
2025-11-24 (about 1 month ago)
Last Updated
2025-11-24 (about 1 month ago)