Confirms that the Royal Elementor Addons plugin accepts file uploads via the Forms widget AJAX handler without authentication. Versions through 1.3.78 validate the MIME type on the client side only, allowing PHP webshell upload and remote code execution.
Is your app exploitable through CVE-2023-5360?
Scan your domain free