CVE-2026-13406 PUBLISHED

Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure

Assigner: WPScan
Reserved: 26.06.2026 Published: 26.08.2026 Updated: 26.08.2026

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.

Product Status

Vendor Unknown
Product Royal Addons for Elementor
Versions Default: unaffected
  • affected from 0 to 1.7.1066 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE