๐Ÿ” CVE Alert

CVE-2026-13404

MEDIUM 5.3

Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
7th

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.

Vendor unknown
Product royal addons for elementor
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown royal addons for elementor

Be the first to know when new medium vulnerabilities affecting unknown royal addons for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Royal Addons for Elementor
0 < 1.7.1066

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c4915a6c-8bf5-46aa-8134-ea490bd6137f/

Credits

Shivamani Vastrala WPScan