{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/royal-elementor-addons--1.3.69/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-5360"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Royal Elementor Addons (\u003c 1.3.69)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Royal Elementor Addons"],"content_html":"\u003cp\u003eThe Royal Elementor Addons plugin for WordPress, prior to version 1.3.69, contains a critical security vulnerability (CVE-2023-5360) that exposes file manipulation capabilities to unauthenticated, remote attackers. The flaw originates from improper access control within the plugin's file handling or upload functions, permitting malicious actors to bypass authentication requirements. By exploiting this gap, an attacker can modify sensitive files, potentially leading to arbitrary code execution, site defacement, or persistent unauthorized access to the web environment. This vulnerability poses a significant risk to site integrity and data confidentiality for any WordPress deployment utilizing affected versions of the plugin. Defenders should prioritize updating the plugin to the latest patched version and audit web server access logs for anomalous POST requests targeting plugin-specific upload endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to gain unauthorized control over site files, potentially resulting in full site compromise, remote code execution, or data exfiltration. Given the ubiquity of WordPress plugins, organizations failing to patch are susceptible to persistent backdoors and long-term compromise of their web-facing infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Royal Elementor Addons to version 1.3.69 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview webserver logs for unauthorized POST requests to plugin directories or suspicious file modifications coinciding with known exploitation patterns of CVE-2023-5360.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) for the WordPress installation directory to detect unauthorized changes to PHP files or configuration settings.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T13:05:30Z","date_published":"2026-09-15T13:05:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-vulnerability/","summary":"A vulnerability in the Royal Elementor Addons plugin for WordPress allows an unauthenticated, remote attacker to manipulate files on the server via improper access control.","title":"Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons","url":"https://feed.craftedsignal.io/briefs/2026-09-royal-elementor-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Royal Elementor Addons (\u003c 1.3.69)","version":"https://jsonfeed.org/version/1.1"}