Vulnerabilities > Royal Elementor Addons > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-05-02 CVE-2024-1567 Unrestricted Upload of File with Dangerous Type vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94.
network
low complexity
royal-elementor-addons CWE-434
critical
9.8
2023-10-31 CVE-2023-5360 Unrestricted Upload of File with Dangerous Type vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
network
low complexity
royal-elementor-addons CWE-434
critical
9.8