CVE-2023-5360

CVE-2023-5360: Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload

Vendor Unknown
Product Royal Elementor Addons and Templates
Published October 31, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

01Description

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Key dates

02Disclosure timeline

October 31, 2023 CVE published
February 13, 2025 Record updated