CVE · Medium

CVE-2026-8118 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1060

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8118 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1060 External Control of File Name or Path Medium 6.5 < 1.7.1060 1.7.1060 2026-06-18

CVE-2026-8118

The Royal Addons for Elementor plugin has a security flaw in its handling of CSV files. Specifically, versions 1.7.1058 to 1.7.1059 are susceptible to an arbitrary file read vulnerability due to inadequate input validation on the settings.table_upload_csv.url value when it's not recognized as an HTTP URL. As a result, authenticated users with Contributor-level access or higher can exploit this weakness by uploading a malicious widget, allowing them to view sensitive files like wp-config.php through the rendered preview.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.