Critical vulnerability identified by wordfence

This topic has 2 replies, 2 voices, and was last updated 1 week ago ago by Andrew Mitchell

  • Avatar: Shafi
    Shafi
    Participant
    January 26, 2026 at 20:26

    Plugin Name: Royal Core
    Current Plugin Version: 1.5.7
    Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Royal Core” until a patched version is available. Get more information.(opens in new tab)
    Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/a6ca0a45-cbb3-419b-a2fd-7427935524d8?source=plugin(opens in new tab)
    Vulnerability Severity: 8.8/10.0 (High)

    Will you solve this issue quickly

    1 Answer
    Avatar: Andrew Mitchell
    Andrew Mitchell
    Support staff
    January 27, 2026 at 10:05

    Hello, Shafi,

    It seems that an error occurred on ThemeForest due to identical plugin names. We do not have a function called royal_restore_backup. In addition, the report refers to a completely different author and developer of the product with the mentioned vulnerability.

    Best regards,
    8Theme Team

    Files is visible for topic creator and
    support staff only.
  • Viewing 2 results - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.Log in/Sign up

We're using our own and third-party cookies to improve your experience and our website. Keep on browsing to accept our cookie policy.