Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-05-14

CVE-2026-6504 - Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-6504

MEDIUM CVSS 6.4 2026-05-14
Threat Entry Updated 2026-04-22

CVE-2026-2373 - Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom post types, such as Contact Form 7 submissions or WooCommerce coupons.

PLUGIN Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-2373

MEDIUM CVSS 5.3 2026-03-17
Scroll to top