CVE-2026-25436
Royal Addons for Elementor – Addons and Templates Kit for Elementor
Minimum safe version
1.7.1058
Update to 1.7.1058 or later to address 78 fixable vulnerabilities
CVE-2026-27421
CVE-2026-4803
CVE-2026-5159
CVE-2026-4024
CVE-2026-6229
CVE-2026-5428
Multiple Plugins and Themes <= (Various Versions) - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2026-5162
CVE-2026-40763
Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing Authorization to Unauthenticated Custom Post Type Contents Exposure
Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass
CVE-2025-13067
CVE-2026-28135
CVE-2025-11363
Royal Elementor Addons <= 1.7.1028 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Multiple Widgets
Royal Elementor Addons and Templates <= 1.7.1020 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-39361
CVE-2024-12120
CVE-2025-39543
CVE-2025-26990
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting
Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting
Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVE-2024-56227
CVE-2024-56226
CVE-2024-56062
CVE-2024-10798
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-9059
WordPress Royal Elementor Addons Plugin <= 1.7.1001 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-9668
CVE-2024-50442
CVE-2024-7417
CVE-2024-8482
CVE-2024-44001
CVE-2024-5818
CVE-2024-4489
CVE-2024-4488
CVE-2024-4087
WordPress Royal Elementor Addons Plugin <= 1.3.975 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-3887
CVE-2024-32786
CVE-2024-3675
CVE-2024-2798
CVE-2024-2799
CVE-2024-3889
CVE-2024-1567
CVE-2024-31236
CVE-2024-1500
CVE-2024-0515
CVE-2024-0513
CVE-2024-0514
CVE-2024-0516
CVE-2024-0512
CVE-2024-0442
CVE-2024-0511
CVE-2023-5922
WordPress Royal Elementor Addons Plugin 1.4.78 is vulnerable to Arbitrary File Upload
CVE-2022-47175
WordPress Royal Elementor Addons Plugin < 1.3.71 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-3709
CVE-2022-4700
CVE-2022-4711
CVE-2022-4701
CVE-2022-4702
CVE-2022-4705
CVE-2022-4708
CVE-2022-4707
CVE-2022-4709
CVE-2022-4703
CVE-2022-4704
CVE-2022-4710
CVE-2022-4103
CVE-2022-4102
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Royal Elementor Addons <= 1.3.55 - Cross-Site Request Forgery