Arbitrary file upload in Royal Elementor Addons - CVE-2023-5360
Published: October 17, 2023 / Updated: August 1, 2025
Vulnerability identifier: #VU82104
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5360
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload. A remote attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Royal Elementor Addons
How to mitigate CVE-2023-5360
Install updates from vendor's website.
Royal Elementor Addons - update to 1.3.79
Links to Public Exploits and PoC-codes
- Exploit #11816 - CVE-2023-5360 (Royal Elementor Addons - Unauthenticated Remote Code Execution) (August 1, 2025)
- Exploit #10445 - CVE-2023-5360 (The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.) (August 30, 2024)
- Exploit #9570 - CVE-2023-5360 (CVE-2023-5360 Exploit/POC) (February 27, 2024)
- Exploit #9500 - CVE-2023-5360 (Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.) (January 15, 2024)
- Exploit #9462 - CVE-2023-5360-PoC (CVE-2023-5360 EXPLOIT ) (December 27, 2023)
- Exploit #9415 - WordPress Royal Elementor Addons RCE (November 28, 2023)