CVE-2023-5360
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
- Affected products
- The Royal Elementor Addons/Templates
- Royal-elementor-addons Royal Elementor Addons
- < 1.3.79
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 81.7% (100th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-10-31
CVE-2023-5360 at NVD
17 known exploits for CVE-2023-5360
Proof-of-concept code and exploit modules indexed by Sploitus
Mephisto
π WordPress Royal Elementor Addons 1.3.78 Shell Upload
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
π WordPress Royal Elementor Addons 1.3.78 Shell Upload
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
WordPress Royal Elementor Addons And Templates Remote Shell Upload
WordPress Royal Elementor Addons Remote Code Execution Exploit
WordPress Royal Elementor Addons RCE
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
Royal Elementor Addons and Templates 1.4.78 - Unauthenticated Arbitrary File Upload
WordPress Royal Elementor 1.3.78 Shell Upload Vulnerability
WordPress Royal Elementor 1.3.78 Shell Upload
Exploit for CVE-2023-4666
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload