CVE-2026-13404: Unknown Royal Addons For Elementor
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.
Affected products
- Unknown Royal Addons For Elementor: before 1.7.1066 (fixed in 1.7.1066)
Published 2026-08-26. Last modified 2026-08-26.