S4E just found a medium-severity finding from log file scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-5360 Scanner

CVE-2023-5360 scanner - Arbitrary File Upload vulnerability in Royal Elementor Addons Plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-5360
9.8
CVSS

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Royal Elementor Addons and Templates
AFFECTED< 1.3.79SAFE ✓≥ 1.3.79
Updated Aug 22, 2026View on NVD →
Detail

The Royal Elementor Addons and Templates WordPress plugin is a tool used by website designers to create stunning and responsive web pages. It includes numerous features such as animations, sticky elements, and various widgets that improve the website's appearance and functionality. The plugin is compatible with the Elementor page builder and is regularly updated to add new features and improve existing ones.

One critical vulnerability affecting the Royal Elementor Addons and Templates WordPress Plugin is CVE-2023-5360. This vulnerability allows for the uploading of arbitrary files such as PHP by unauthenticated users due to poor validation of files. When exploited, an attacker could execute malicious code on the website, resulting in dire consequences such as data breaches and unauthorized access. This vulnerability makes it possible for attackers to take control of the web server, allowing them to exploit sensitive data. 

When exploited, the CVE-2023-5360 vulnerability can bring severe consequences to your website's data and security. It could lead to malicious code execution, data theft, and unauthorized access. Hackers could gain full control over your website and consequently cause irreparable damages. The vulnerability exposes the website to various threats, including phishing attacks, malware distribution, and ransomware attacks. Therefore, it is essential to take proactive measures to mitigate the risk and protect your website from this vulnerability. 

As a website owner or manager, the security of your website is critical. The s4e.io platform provides pro features that enable website owners to check for known vulnerabilities continually. With vast vulnerability databases and an easy-to-use interface, you can easily and quickly learn about vulnerabilities in your digital assets. By subscribing to their services, you can also receive alerts for new vulnerabilities and keep your website protected from potential threats. Therefore, take proactive measures and keep your website security updated with the latest technologies for added protection.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners are advised to take the following precautions:

  • Upgrade to the latest version of the Royal Elementor plugin
  • Install a reliable security plugin that can detect and block any malicious activity
  • Regularly monitor the website for unusual traffic and suspicious activity
  • Set strict file permissions on the server
  • Follow best practices for web application security, such as using secure passwords and enabling SSL encryption.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.