SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-13402

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Royal Addons for Elementor WordPress plugin prior to version 1.7.1063 is vulnerable due to inadequate checks on the post status of menu items and their referenced templates in a REST endpoint. This flaw allows unauthenticated users to access and retrieve rendered HTML content from private or draft Elementor templates linked to non-public navigation menus. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exposure of sensitive content.

CVE
CVE-2026-13402
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.