CVE-2026-13404
Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init
CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
7th
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.
| Vendor | unknown |
| Product | royal addons for elementor |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown royal addons for elementor
Be the first to know when new medium vulnerabilities affecting unknown royal addons for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Royal Addons for Elementor
0 < 1.7.1066
References
Credits
Shivamani Vastrala WPScan