CVE-2023-5360

CRITICAL EXPLOITED IN THE WILD NUCLEI

WordPress Royal Elementor Addons RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2023-5360 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 12 public exploits from researchers including 4m3rr0r, phankz, Chocapikk, including a Metasploit module exploits/multi/http/wp_royal_elementor_addons_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in WordPress Plugin Royal Elementor Addons <= 1.3.78, leading to Remote Code Execution (RCE). It retrieves a nonce from the target site and uploads a malicious PHP shell.

Description

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Exploits (12)

exploitdb WORKING POC
by 4m3rr0r · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52127

This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in WordPress Plugin Royal Elementor Addons <= 1.3.78, leading to Remote Code Execution (RCE). It retrieves a nonce from the target site and uploads a malicious PHP shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Plugin Royal Elementor Addons <= 1.3.78
No auth needed
Prerequisites: Target running WordPress with vulnerable Royal Elementor Addons plugin · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 13 stars
by phankz · poc
https://github.com/phankz/Worpress-CVE-2023-5360

This repository contains a Python-based exploit for CVE-2023-5360, targeting a shell upload vulnerability in WordPress Royal Elementor Addons version 1.3.78. The exploit uses obfuscation techniques and requires Python 3.11+ with pycryptodome.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Royal Elementor Addons 1.3.78
No auth needed
Prerequisites: Python 3.11+ · pycryptodome library · target running vulnerable WordPress plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2023-5360

This repository contains a functional exploit for CVE-2023-5360, an unauthenticated file upload vulnerability in the WordPress Royal Elementor Addons and Templates plugin. The exploit uploads a malicious PHP file to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Royal Elementor Addons and Templates < 1.3.79
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and active · Target must be accessible via HTTP/HTTPS
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 5 stars
by Pushkarup · remote
https://github.com/Pushkarup/CVE-2023-5360

This PoC exploits CVE-2023-5360, a file upload vulnerability in the Royal Elementor Addons WordPress plugin, allowing arbitrary PHP file uploads via a crafted request to admin-ajax.php. It includes a PHP shell upload form and logs vulnerable/exploited targets.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Royal Elementor Addons WordPress plugin (version not specified)
No auth needed
Prerequisites: Target must have the vulnerable Royal Elementor Addons plugin installed · WordPress site must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by tucommenceapousser · remote
https://github.com/tucommenceapousser/CVE-2023-5360

This repository contains a Python-based exploit for CVE-2023-5360, which appears to target a file upload vulnerability. The exploit includes a PHP shell upload script designed to execute arbitrary commands and display system information.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Unknown (likely a web application with file upload functionality)
No auth needed
Prerequisites: Target with vulnerable file upload functionality · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by sagsooz · poc
https://github.com/sagsooz/CVE-2023-5360

This exploit PoC targets a shell upload vulnerability in WordPress Royal Elementor Addons plugin version 1.3.78 (CVE-2023-5360). The exploit.py file contains obfuscated Python code that likely automates the upload of a malicious shell.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Royal Elementor Addons 1.3.78
No auth needed
Prerequisites: Access to the WordPress site with the vulnerable plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by X3RX3SSec · remote
https://github.com/X3RX3SSec/CVE-2023-5360

This is a functional exploit for CVE-2023-5360, an unauthenticated file upload vulnerability in the Royal Elementor Addons and Templates WordPress plugin before 1.3.79. It automates the extraction of a nonce, uploads a PHP shell (either a simple webshell or a reverse shell), and optionally starts a listener.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Royal Elementor Addons and Templates WordPress plugin < 1.3.79
No auth needed
Prerequisites: Target must be running vulnerable version of Royal Elementor Addons and Templates plugin · Access to a WordPress page using Elementor
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by mdelaclaire · poc
https://gitlab.com/mdelaclaire/CVE-2023-5360

This repository contains a functional exploit for CVE-2023-5360, which appears to be a file upload vulnerability allowing arbitrary file uploads to a web server. The exploit includes a PHP shell upload script and a Python-based exploit script to automate the attack.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Unknown (likely a web application with a file upload vulnerability)
No auth needed
Prerequisites: Target web application with vulnerable file upload functionality · Network access to the target
devstral-2 · analyzed Feb 23, 2026 Full analysis →
nomisec WORKING POC
by LaviruDilshan · remote
https://github.com/LaviruDilshan/CVE-2023-5360-exploit-with-native-libraries

This is a fully functional Python-based exploit for CVE-2023-5360, targeting Royal Elementor Addons ≤ 1.3.78. It leverages unauthenticated arbitrary file upload to achieve RCE by bypassing client-side nonce validation and file extension checks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Royal Elementor Addons and Templates (WordPress plugin) ≤ 1.3.78
No auth needed
Prerequisites: WordPress with vulnerable plugin installed · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Jenderal92 · remote
https://github.com/Jenderal92/WP-CVE-2023-5360

This repository contains a Python-based exploit for CVE-2023-5360, an unauthenticated arbitrary file upload vulnerability in Royal Elementor Addons and Templates <= 1.3.78. The exploit uploads a malicious PHP file to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Royal Elementor Addons and Templates <= 1.3.78
No auth needed
Prerequisites: Target running vulnerable version of Royal Elementor Addons and Templates · Access to the target's admin-ajax.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by nastar-id · remote
https://github.com/nastar-id/CVE-2023-5360

This PoC exploits CVE-2023-5360, an arbitrary file upload vulnerability in a WordPress plugin, allowing attackers to upload a malicious PHP shell. The script automates the process of retrieving a nonce, uploading the shell, and verifying its execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress plugin (likely a specific plugin, version <1.3.78)
No auth needed
Prerequisites: Target URL list · Malicious PHP shell file named 'up.ph$p'
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Fioravante Souza, Valentin Lobstein · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_royal_elementor_addons_rce.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress Royal Elementor Addons plugin versions prior to 1.3.79, allowing remote code execution via a malicious PHP file upload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Royal Elementor Addons and Templates plugin < 1.3.79
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and active · WordPress site must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload
CRITICALVERIFIEDby theamanrawat
Shodan: http.html:/plugins/royal-elementor-addons/
FOFA: body=/plugins/royal-elementor-addons/

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.8169
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-10-13
InTheWild.io 2023-10-16
CWE
CWE-434
Status published
Products (1)
royal-elementor-addons/royal_elementor_addons < 1.3.79
Published Oct 31, 2023
Tracked Since Feb 18, 2026