The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 32,531 live websites that are affected by CVE-2025-0393.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 32,531 live websites (62.82% of Royal Elementor Addons install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 111 versions ( 92.50% of all versions) |
![]() | 9,494 websites |
![]() | 4,574 websites |
![]() | 2,760 websites |
![]() | 2,156 websites |
![]() | 1,569 websites |
![]() | 943 websites |
![]() | 937 websites |
![]() | 785 websites |
![]() | 784 websites |
![]() | 742 websites |
.com | 13,206 websites |
.com.br | 2,506 websites |
.de | 1,643 websites |
.org | 1,278 websites |
.fr | 1,200 websites |
.it | 915 websites |
.pl | 631 websites |
.net | 627 websites |
.ru | 604 websites |
.co.uk | 570 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | *** | |
**********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
***********.net | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*****.clinic | ![]() | **,*** | |
************.com | ![]() | ***,*** |
FAQ