Sploitus

CVE-2023-5360

17 known exploits for CVE-2023-5360

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Royal-elementor-addons Royal Elementor Addons
< 1.3.79
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
81.7% (100th percentile)
Weakness
CWE-434
NVD status
Modified
Published
2023-10-31
CVE-2023-5360 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2023-5360

Proof-of-concept code and exploit modules indexed by Sploitus

Mephisto
2026-05-21 InMyMine7GITHUB
πŸ“„ WordPress Royal Elementor Addons 1.3.78 Shell Upload
2026-02-06 indoushkaPACKETSTORMPHP
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
2025-12-27 LaviruDilshanGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
2025-07-14 X3RX3SSecGITHUB
πŸ“„ WordPress Royal Elementor Addons 1.3.78 Shell Upload
2025-04-07 Sheikh Mohammad HasanPACKETSTORMPython
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
2025-04-05 4m3rr0rEXPLOITDBPython
WordPress Royal Elementor Addons And Templates Remote Shell Upload
2023-11-29 Valentin Lobstein, Fioravante Souza, metasploit.comPACKETSTORMRuby
WordPress Royal Elementor Addons Remote Code Execution Exploit
2023-11-28 metasploitZDTRuby
WordPress Royal Elementor Addons RCE
2023-11-23 Fioravante Souza, Valentin LobsteinMETASPLOITRuby
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
2023-11-05 PushkarupGITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
2023-11-03 Jenderal92GITHUB
Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal_Elementor_Addons
2023-11-02 ChocapikkGITHUB
Royal Elementor Addons and Templates 1.4.78 - Unauthenticated Arbitrary File Upload
2023-10-23 Fioravante SouzaWPEXPLOITPython
WordPress Royal Elementor 1.3.78 Shell Upload Vulnerability
2023-10-16 Fioravante SouzaZDT
WordPress Royal Elementor 1.3.78 Shell Upload
2023-10-16 Fioravante Souza, wordfence.comPACKETSTORM
Exploit for CVE-2023-4666
2023-10-14 IRB0TGITHUB
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
2023-10-09 Fioravante SouzaWPEXPLOITPython