SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13405

MEDIUM · CVSS 6.6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Royal Addons for Elementor WordPress plugin prior to version 1.7.1066 is vulnerable due to improper sanitization of custom widget markup, enabling users with manage_options capability to execute arbitrary PHP code. This flaw poses a medium risk as it could lead to unauthorized code execution on affected WordPress sites. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-13405
Severity
MEDIUM
CVSS
6.6
EPSS
0.27%
WordPress

Original NVD Description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.