PatchSiren

wproyal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wproyal CVE published 2026-05-02

CVE-2026-6229

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter, and the subsequent use of these URLs in fopen() calls without blocking internal or priv [truncated]

MEDIUM wproyal CVE published 2026-04-24

CVE-2026-5428

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attac [truncated]

MEDIUM wproyal CVE published 2026-04-08

CVE-2026-39627

A Missing Authorization vulnerability in the Ashe theme for WordPress, affecting versions up to and including 2.266, has been identified. This issue allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. It can be exploited over the network with low privileges [truncated]

MEDIUM wproyal CVE published 2026-04-04

CVE-2026-0664

The Royal Addons for Elementor plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'button_text' parameter in all versions up to, and including, 1.7.1049. This is due to insufficient input sanitization and output escaping. Authenticated attackers with contributor level access and above can inject arbitrary web scripts in pages that will execute when a user accesses an injected pag [truncated]