CVE · High

CVE-2025-13067 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1050

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13067 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1050 Unrestricted Upload of File with Dangerous Type High 8.8 < 1.7.1050 1.7.1050 2026-03-10

CVE-2025-13067

The Royal Addons for Elementor plugin has a security flaw in all versions up to 1.7.1049 that allows attackers with author-level access or higher to bypass file validation checks. Specifically, files named "main.php" can evade sanitization, enabling malicious uploads of arbitrary files to the affected site's server. This vulnerability could potentially lead to remote code execution by an attacker.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.