Junglewise Threat Intelligence

CVE-2026-8118: Royal Addons for Elementor arbitrary file read in wpr_get_csv_handle

CVE-2026-8118 · Severity: medium · CVSS 6.5 · Published 2026-06-19

Technologies: WPRoyal Royal Addons for Elementor. Vendors: WPRoyal.

Executive brief

The Royal Addons for Elementor plugin for WordPress is vulnerable to an arbitrary file read flaw. This plugin provides additional design elements and templates for the Elementor page builder. An attacker with basic contributor-level access can exploit this to view sensitive internal files, such as configuration files containing database credentials, which could lead to a full site takeover.

Technical details

The vulnerability exists in the wpr_get_csv_handle() helper function, which was introduced as a patch for a previous vulnerability. The function fails to properly validate the 'settings.table_upload_csv.url' parameter; if the value is not a valid HTTP URL, the code falls back to using is_readable() and fopen() on the raw input without path traversal blocks or extension checks. Authenticated attackers with Contributor-level permissions or higher can use the Elementor 'save_builder' endpoint to inject a crafted path into a 'wpr-data-table' widget. When the widget is rendered in a preview, the plugin returns the contents of the specified local file, such as wp-config.php, to the attacker.

Affected products

  • wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059

Timeline

  • 2026-06-19: disclosed: Vulnerability published by Wordfence and NVD

References