Arbitrary Taxonomy Data Disclosure in Royal Addons for Elementor Plugin by WordPress
CVE-2026-13406
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-13406?
The Royal Addons for Elementor plugin prior to version 1.7.1066 is vulnerable to an arbitrary data exposure flaw, where it fails to implement necessary capability or nonce checks. This oversight allows unauthenticated users to gain access to sensitive taxonomy term data, including names and IDs, from non-public taxonomies. As a result, this vulnerability can potentially expose critical information, compromising the security and integrity of WordPress sites utilizing this plugin.
Affected Version(s)
Royal Addons for Elementor 0 < 1.7.1066
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.