CVE-2025-0393

Royal Elementor Addons and Templates <= 1.7.1006 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 32,531 live websites that are affected by CVE-2025-0393.

Test my site




Affected Software

Product  Royal Elementor Addons
Category Wordpress Plugins
Vulnerable Domains32,531 live websites (62.82% of Royal Elementor Addons install base)
Vulnerable Versions
  • from 0 through 1.7.1006
Vulnerable Versions Count111 versions ( 92.50% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jan 14, 2025
  • Updated - Jan 14, 2025

Credits

  • Matthew Rollings (finder)

CVE-2025-0393 usage by Country

United States9,494 websites



Germany4,574 websites
France2,760 websites
Cyprus2,156 websites
Brazil1,569 websites
GB943 websites
Italy937 websites
Poland785 websites
Spain784 websites
Russia742 websites

CVE-2025-0393 usage by TLD

.com13,206 websites
.com.br2,506 websites
.de1,643 websites
.org1,278 websites
.fr1,200 websites
.it915 websites
.pl631 websites
.net627 websites
.ru604 websites
.co.uk570 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-0393

Top websites that are affected by CVE-2025-0393. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***
**********.com United States**,***
******.com Germany**,***
*********.com United States**,***
*********.com United States**,***
******.com United States**,***
***********.net United States**,***
***********.com United States**,***
*****.clinic Israel**,***
************.com United States***,***
See full domain list

FAQ

CVE-2025-0393 is Cross-Site Request Forgery (CSRF) in Royal Elementor Addons
A total of 32,531 websites have been identified as vulnerable to CVE-2025-0393, discovered through global website indexing conducted by WebTechSurvey.
Royal Elementor Addons is susceptible to CVE-2025-0393 vulnerability.
Royal Elementor Addons versions before, and including, 1.7.1006 are vulnerable to CVE-2025-0393.