Feed/CVE-2023-5360
CVE-2023-5360CRITICALCVSS 9.8

CVE-2023-5360

Published Oct 31, 2023·Updated Jun 17, 2026

NVD Description

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Public Exploits & PoCs10 found

PoC: CVE-2023-5360

Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.

1

PoC: CVE-2023-5360-exploit-with-native-libraries

CVE-2023-5360 PoC: Unauthenticated arbitrary file upload leading to RCE in Royal Elementor Addons (≤ 1.3.78), written in pure Python.

PoC: CVE-2023-5360

Royal Elementor Addons - Unauthenticated Remote Code Execution

PoC: CVE-2023-5360-PoC

CVE-2023-5360 EXPLOIT

PoC: CVE-2023-5360

CVE-2023-5360 Exploit/POC

PoC: CVE-2023-5360

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

PoC: WP-CVE-2023-5360

Python 2.7

PoC: CVE-2023-5360

Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.

PoC: CVE-2023-5360

CVE-2023-5360

PoC: CVE-2023-5360

CVE-2023-5360 Auto Shell Upload WordPress Royal Elementor 1.3.78 Shell Upload

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free