CVE-2023-5360 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 81.7% (pctl 100)
Patch early
A public exploit exists.
Description
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 81.7% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-10-31 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| royal-elementor-addons | royal elementor addons |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload | 2025-04-05 |
References
- http://packetstormsecurity.com/files/175992/WordPress-Royal-Elementor-Addons-And-Templates-Remote-Shell-Upload.html
- https://wpscan.com/vulnerability/281518ff-7816-4007-b712-63aed7828b34
- http://packetstormsecurity.com/files/175992/WordPress-Royal-Elementor-Addons-And-Templates-Remote-Shell-Upload.html
- https://wpscan.com/vulnerability/281518ff-7816-4007-b712-63aed7828b34
→ the Explorer · watch your stack · NVD