Royal Elementor Addons and Templates, CVE-2026-13406
- CVE, Research URL
- Application
- Published on
- Aug 26, 2026
- Research Description
- The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.
- Affected versions
-
max 1.7.1066.
- Status
-
vulnerable