CVE-2025-11363: Unknown Royal Addons For Elementor
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.
Affected products
- Unknown Royal Addons For Elementor: before 1.7.1037 (fixed in 1.7.1037)
Published 2025-12-15. Last modified 2026-10-07.