Vulnerabilities > Royal Elementor Addons > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-10-31 CVE-2023-5360 Unrestricted Upload of File with Dangerous Type vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
network
low complexity
royal-elementor-addons CWE-434
critical
9.8