Skip to main content
CRITICAL

CVE-2023-5360

CVSS v3

9.8

CRITICAL

EPSS Score

81.7 %

exploit probability, as of 2026-10-03

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Technical details

Published
2023-10-31
Exploit-DB
EDB-52127

Frequently asked questions

What is CVE-2023-5360?

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Is CVE-2023-5360 actively exploited?

Active exploitation of CVE-2023-5360 has not been confirmed. Its EPSS score was 81.7% on 2026-10-03, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-5360?

CVE-2023-5360 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-5360 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key