cleantalk
Vulnerabilities and Security Researches

Royal Elementor Addons and Templates, CVE-2026-13404

CVE, Research URL

CVE-2026-13404

Published on
Aug 26, 2026
Research Description
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.
Affected versions
max 1.7.1066.
Status
vulnerable