CVE-2026-13405 PUBLISHED

Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder

Assigner: WPScan
Reserved: 26.06.2026 Published: 20.08.2026 Updated: 20.08.2026

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.

Product Status

Vendor Unknown
Product Royal Addons for Elementor
Versions Default: unaffected
  • affected from 0 to 1.7.1066 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE