CVE-2025-11363

The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-15 06:15

Updated : 2026-06-17 08:30


NVD link : CVE-2025-11363

Mitre link : CVE-2025-11363

CVE.ORG link : CVE-2025-11363


JSON object : View

Products Affected

No product.

CWE

No CWE.