Royal Addons for Elementor
cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:wordpress:*:*
- <= 1.7.1049
A vulnerability allowing arbitrary file upload has been identified in the Royal Addons for Elementor plugin for WordPress, affecting all versions through 1.7.1049. The issue arises from inadequate file type validation, which fails to properly sanitize files named 'main.php'. This flaw enables authenticated attackers with author-level access or higher to upload arbitrary files to the server, potentially leading to remote code execution.
Exploitation of this vulnerability could allow for arbitrary file upload, with the potential for remote code execution if the uploaded file is executed on the server.
Users are advised to update the Royal Addons for Elementor plugin to version 1.7.1050 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.