CVE-2026-13404 PUBLISHED

Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init

Assigner: WPScan
Reserved: 26.06.2026 Published: 26.08.2026 Updated: 26.08.2026

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.

Product Status

Vendor Unknown
Product Royal Addons for Elementor
Versions Default: unaffected
  • affected from 0 to 1.7.1066 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE