SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13404

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Royal Addons for Elementor WordPress plugin prior to version 1.7.1066 is vulnerable to unauthorized modifications of post metadata, as it lacks proper capability and ownership checks. This flaw allows unauthenticated users to alter like-count and visitor-tracking data for any post, including private and draft content, potentially leading to misinformation and privacy breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-13404
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%
WordPress

Original NVD Description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.