CVE Database /
CVE-2023-5360
CVE · Critical
CVE-2023-5360 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-5360
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.8
|
< 1.7.1
|
1.7.1 |
2023-10-09 |
—
|
CVE-2023-5360
The Royal Addons for Elementor plugin is vulnerable to arbitrary file uploads in versions up to 1.3.78 due to inadequate file type validation in the handle_file_upload() function accessed through AJAX. Attackers can manipulate the allowed_file_types parameter by appending special characters to bypass the file type filter, enabling unauthenticated users to upload malicious files to the server. This vulnerability could allow attackers to achieve remote code execution on affected WordPress installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings