← Vulnerability feed

Vulnerability record · CVE-2023-5360 · published 31 October 2023

CVE-2023-5360: Royal Elementor Addons WordPress plugin unauthenticated file upload RCE

Royal Elementor Addons · Royal Elementor Addons

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 fails to properly validate uploaded files, allowing unauthenticated users to upload arbitrary files such as PHP. Because the uploaded PHP can be executed by the web server, this is a direct path to remote code execution on the affected site.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.4% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS, plus public exploit references, makes this an urgent patch.

What it is

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 fails to properly validate uploaded files, allowing unauthenticated users to upload arbitrary files such as PHP. Because the uploaded PHP can be executed by the web server, this is a direct path to remote code execution on the affected site.

Impact

An unauthenticated attacker can upload and execute arbitrary PHP, gaining remote code execution on the WordPress host, which typically means full site compromise and potential server-level access depending on configuration.

Attack surface

Reachable over the network through the plugin's file upload functionality with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed WordPress site running a vulnerable version is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.817 (99.6th percentile) and WPScan references are tagged Exploit, indicating public exploit code exists. No ransomware group usage is documented in the record.

What to do

  • Update the Royal Elementor Addons and Templates plugin to version 1.3.79 or later immediately.
  • If patching cannot be done at once, disable or remove the plugin until it can be updated.
  • Restrict execution of PHP in WordPress upload directories via web server configuration.
  • Add a WAF rule blocking PHP file uploads to plugin upload endpoints as a temporary control.
  • Audit the site for unexpected files in uploads and other writable directories after patching.

Detection

  • Monitor web server and plugin logs for POST requests to Royal Elementor Addons upload endpoints followed by access to newly written files.
  • Alert on creation of PHP files in wp-content/uploads or other writable directories.
  • Scan the filesystem for recently modified or unexpected PHP files and compare against known-good baselines.
  • Review web server logs for requests to newly uploaded PHP paths returning 200 responses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5360 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-32786Royal-elementor-addons royal elementor addons authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Add…EPSS 0.46%9.8CVE-2024-1567Royal-elementor-addons royal elementor addons unrestricted file upload vulnerabilityThe Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_…EPSS 1.1%8.8CVE-2025-1441Royal-elementor-addons royal elementor addons cross-site request forgery vulnerabilityThe Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1…EPSS 0.22%8.8CVE-2022-47175Royal-elementor-addons royal elementor addons cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 versions.EPSS 0.26%8.8CVE-2022-4700Royal-elementor-addons royal elementor addons improper access control vulnerabilityThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in vers…EPSS 0.81%8.8CVE-2022-4701Royal-elementor-addons royal elementor addons improper authorization vulnerabilityThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in ve…EPSS 0.75%8.1CVE-2022-4703Royal-elementor-addons royal elementor addons improper access control vulnerabilityThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versio…EPSS 0.94%8.1CVE-2022-4704Royal-elementor-addons royal elementor addons improper access control vulnerabilityThe Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in version…EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2023-5360), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.