The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 9,942 live websites that are affected by CVE-2025-0393.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 9,942 live websites (15% of Royal Elementor Addons install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 103 versions ( 67% of all versions) |
| 1,558 websites | |
| 1,033 websites | |
| 841 websites | |
| 749 websites | |
| 671 websites | |
| 457 websites | |
| 368 websites | |
| 352 websites | |
| 335 websites | |
| 276 websites |
| .com | 3,590 websites |
| .com.br | 695 websites |
| .de | 502 websites |
| .it | 501 websites |
| .org | 377 websites |
| .fr | 359 websites |
| .ru | 303 websites |
| .pl | 218 websites |
| .net | 175 websites |
| .co.uk | 154 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| ****.com | **,*** | ||
| *********.com | **,*** | ||
| ******.com | **,*** | ||
| ************.com | ***,*** | ||
| ******.me | ***,*** | ||
| *********.org | ***,*** | ||
| ******.com | ***,*** | ||
| *********************.com | ***,*** | ||
| ****.***.my | ***,*** |
FAQ