Royal Addons For Elementor

WordPress plugin · royal-addons-for-elementor · WordPress.org ↗
0
Critical
0
High
7
Known total
0
Unfixed
Running Royal Addons For Elementor on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 6.1
Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails
CVE.org
>=0, <1.7.1067 v1.7.1067 CVE-2026-13407 Sep 16, 2026
MEDIUM
CVSS 6.8
Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect Settings
CVE.org
>=0, <1.7.1066 v1.7.1066 CVE-2026-19226 Aug 26, 2026
MEDIUM
CVSS 5.3
Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init
CVE.org
>=0, <1.7.1066 v1.7.1066 CVE-2026-13404 Aug 26, 2026
MEDIUM
CVSS 5.3
Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure
CVE.org
>=0, <1.7.1066 v1.7.1066 CVE-2026-13406 Aug 26, 2026
MEDIUM
CVSS 6.6
Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder
CVE.org
>=0, <1.7.1066 v1.7.1066 CVE-2026-13405 Aug 20, 2026
MEDIUM
CVSS 5.4
Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget
CVE.org
>=0, <1.7.1065 v1.7.1065 CVE-2026-19217 Aug 12, 2026
MEDIUM
CVSS 5.3
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
CVE.org
>=0, <1.7.1063 v1.7.1063 CVE-2026-13402 Jul 17, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.