Skip to content
Threat Feed
medium advisory

Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons

A vulnerability in the Royal Elementor Addons plugin for WordPress allows an unauthenticated, remote attacker to manipulate files on the server via improper access control.

CVE search metadata

CVE search record: CVE-2023-5360. Severity: critical. CVSS: 9.8. EPSS: 81.69%. KEV: no. Product: Royal Elementor Addons (< 1.3.69). Brief: Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons. Brief link: https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-vulnerability/

The Royal Elementor Addons plugin for WordPress, prior to version 1.3.69, contains a critical security vulnerability (CVE-2023-5360) that exposes file manipulation capabilities to unauthenticated, remote attackers. The flaw originates from improper access control within the plugin's file handling or upload functions, permitting malicious actors to bypass authentication requirements. By exploiting this gap, an attacker can modify sensitive files, potentially leading to arbitrary code execution, site defacement, or persistent unauthorized access to the web environment. This vulnerability poses a significant risk to site integrity and data confidentiality for any WordPress deployment utilizing affected versions of the plugin. Defenders should prioritize updating the plugin to the latest patched version and audit web server access logs for anomalous POST requests targeting plugin-specific upload endpoints.

Impact

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized control over site files, potentially resulting in full site compromise, remote code execution, or data exfiltration. Given the ubiquity of WordPress plugins, organizations failing to patch are susceptible to persistent backdoors and long-term compromise of their web-facing infrastructure.

Recommendation

  • Update Royal Elementor Addons to version 1.3.69 or later immediately.
  • Review webserver logs for unauthorized POST requests to plugin directories or suspicious file modifications coinciding with known exploitation patterns of CVE-2023-5360.
  • Implement file integrity monitoring (FIM) for the WordPress installation directory to detect unauthorized changes to PHP files or configuration settings.

Immediate actions

Upgrade Royal Elementor Addons to version 1.3.69 or later.

IT Operations 24h

Mitigations

Upgrade Royal Elementor Addons to 1.3.69 or later.

immediate IT Operations

CVE-2023-5360