Security Advisory

CVE-2026-13404

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-26 06:00:18
Last updated 2026-08-26 14:43:10
Assigner WPScan
CVSS score 5.3
State PUBLISHED

Description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.