CVE · Critical

CVE-2023-5360 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5360 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.3.79 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 1.7.1 1.7.1 2023-10-09

CVE-2023-5360

The Royal Addons for Elementor plugin is vulnerable to arbitrary file uploads in versions up to 1.3.78 due to inadequate file type validation in the handle_file_upload() function accessed through AJAX. Attackers can manipulate the allowed_file_types parameter by appending special characters to bypass the file type filter, enabling unauthenticated users to upload malicious files to the server. This vulnerability could allow attackers to achieve remote code execution on affected WordPress installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.