All verified exploits

CVE-2023-5360 Unauthenticated Arbitrary File Upload

Deterministic critical Royal Elementor Addons CISA KEV Added cve-verified-cve-2023-5360

Confirms that the Royal Elementor Addons plugin accepts file uploads via the Forms widget AJAX handler without authentication. Versions through 1.3.78 validate the MIME type on the client side only, allowing PHP webshell upload and remote code execution.

Is your app exploitable through CVE-2023-5360?

Scan your domain free