Arbitrary Code Execution Vulnerability in Royal Addons for Elementor WordPress Plugin
CVE-2026-13405
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-13405?
The Royal Addons for Elementor plugin for WordPress prior to version 1.7.1066 contains a critical vulnerability that fails to properly sanitize custom widget markup when writing to a file. This oversight can be exploited by users with the manage_options capability, and in WordPress Multisite environments, by non-super subsite administrators lacking code-execution abilities, enabling them to execute arbitrary PHP code. It is essential for administrators to update to the latest version to mitigate potential threats associated with this flaw.
Affected Version(s)
Royal Addons for Elementor 0 < 1.7.1066
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.