Vulnerability record · CVE-2023-5360 · published 31 October 2023
CVE-2023-5360: Royal Elementor Addons WordPress plugin unauthenticated file upload RCE
Royal Elementor Addons · Royal Elementor Addons
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 fails to properly validate uploaded files, allowing unauthenticated users to upload arbitrary files such as PHP. Because the uploaded PHP can be executed by the web server, this is a direct path to remote code execution on the affected site.
Description
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS, plus public exploit references, makes this an urgent patch.
What it is
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 fails to properly validate uploaded files, allowing unauthenticated users to upload arbitrary files such as PHP. Because the uploaded PHP can be executed by the web server, this is a direct path to remote code execution on the affected site.
Impact
An unauthenticated attacker can upload and execute arbitrary PHP, gaining remote code execution on the WordPress host, which typically means full site compromise and potential server-level access depending on configuration.
Attack surface
Reachable over the network through the plugin's file upload functionality with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed WordPress site running a vulnerable version is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.817 (99.6th percentile) and WPScan references are tagged Exploit, indicating public exploit code exists. No ransomware group usage is documented in the record.
What to do
- Update the Royal Elementor Addons and Templates plugin to version 1.3.79 or later immediately.
- If patching cannot be done at once, disable or remove the plugin until it can be updated.
- Restrict execution of PHP in WordPress upload directories via web server configuration.
- Add a WAF rule blocking PHP file uploads to plugin upload endpoints as a temporary control.
- Audit the site for unexpected files in uploads and other writable directories after patching.
Detection
- Monitor web server and plugin logs for POST requests to Royal Elementor Addons upload endpoints followed by access to newly written files.
- Alert on creation of PHP files in wp-content/uploads or other writable directories.
- Scan the filesystem for recently modified or unexpected PHP files and compare against known-good baselines.
- Review web server logs for requests to newly uploaded PHP paths returning 200 responses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-5360 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-5360), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.