Royal Elementor Addons and Templates, CVE-2026-13404
- CVE, Research URL
- Application
- Published on
- Aug 26, 2026
- Research Description
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.
- Affected versions
-
max 1.7.1066.
- Status
-
vulnerable