Unprotected Metadata Manipulation in Royal Addons for Elementor Plugin
CVE-2026-13404
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13404?
The Royal Addons for Elementor WordPress plugin prior to version 1.7.1066 lacks proper capability and ownership checks, relying solely on a publicly accessible nonce. This oversight permits unauthorized users to alter like-counts and visitor-tracking metadata for arbitrary posts, which includes private and draft content. As a result, this vulnerability can lead to the manipulation of post metadata without authentication, exposing sensitive data and undermining the integrity of the content management process.
Affected Version(s)
Royal Addons for Elementor 0 < 1.7.1066
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.