CVE Database /
CVE-2026-13402
CVE
CVE-2026-13402 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1063
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13402
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1063 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 1.7.1063
|
1.7.1063 |
2026-06-26 |
—
|
CVE-2026-13402
The Royal Addons for Elementor plugin's REST endpoint fails to verify the visibility of referenced templates and menu items, enabling unauthorized access to sensitive template data. This vulnerability affects versions prior to 1.7.1063, where private or draft templates can be retrieved via non-public navigation links. Unauthenticated users can exploit this flaw to obtain restricted content.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings