CVE · High

CVE-2026-28135 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1053

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-28135 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1053 Inclusion of Functionality from Untrusted Control Sphere High 8.2 < 1.7.1053 1.7.1053 2026-02-26

CVE-2026-28135

The Royal Addons for Elementor plugin has a security flaw that allows anyone to carry out a specific task without needing permission, due to a missing check in its code affecting all versions prior to 1.7.1052. This oversight enables malicious users to execute actions they shouldn't be able to do normally.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.