CVE-2025-0393

Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 9,942 live websites that are affected by CVE-2025-0393.

Run a Free Instant Scan




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains9,942 live websites (15% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.7.1006
Vulnerable Versions Count103 versions ( 67% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jan 14, 2025
  • Updated - Apr 8, 2026

Credits

  • Matthew Rollings (finder)

Website Distribution by Country

Number of websites using CVE-2025-0393
United States1,558 websites



Germany1,033 websites
France841 websites
Brazil749 websites
Italy671 websites
India457 websites
Russia368 websites
GB352 websites
Spain335 websites
Poland276 websites

Website Distribution by TLD

Number of websites using CVE-2025-0393
.com3,590 websites
.com.br695 websites
.de502 websites
.it501 websites
.org377 websites
.fr359 websites
.ru303 websites
.pl218 websites
.net175 websites
.co.uk154 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-0393

Top websites that are affected by CVE-2025-0393. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
****.com Germany**,***
*********.com United States**,***
******.com United States**,***
************.com United States***,***
******.me United States***,***
*********.org United States***,***
******.com United States***,***
*********************.com United States***,***
****.***.my Malaysia***,***
See full domain list

FAQ

CVE-2025-0393 is Cross-Site Request Forgery (CSRF) in Royal Elementor Addons
A total of 9,942 websites have been identified as vulnerable to CVE-2025-0393, based on global website indexing conducted by WebTechSurvey.
The Royal Elementor Addons is affected by the CVE-2025-0393 vulnerability.
Royal Elementor Addons versions up to and including 1.7.1006 are vulnerable to CVE-2025-0393.