CVE · Medium

CVE-2025-11363 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1037

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11363 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1037 Unrestricted Upload of File with Dangerous Type Medium 5.3 < 1.7.1037 1.7.1037 2025-11-24

CVE-2025-11363

The Royal Addons for Elementor plugin has an issue with its security settings, allowing unauthorized uploads of media files through the 'wpr_addons_upload_file' endpoint in versions up to and including 1.7.1036. This vulnerability enables malicious users to upload files without proper authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.