CVE-2026-13405Disclosure

LOWCVSS 6.6 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-20: 3Technical Details · 2026-08-20: 308-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-13405 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, … https://www.cve.org/CVERecord?id=CVE-2026-13405

    Post summary

    The post discloses that Royal Addons for Elementor before version 1.7.1066 fails to sanitize widget markup, leading to potential execution of malicious code.

    02032920
    58.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13405 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, … https://www.cve.org/CVERecord?id=CVE-2026-13405 ----- Traducción: CVE-2026-13405 The… https://infoflow.cloud`

    Post summary

    A new CVE (2026‑13405) has been disclosed for the Royal Addons for Elementor WordPress plugin, indicating that unsanitised widget markup can lead to file execution (RCE). No PoC, exploit, or patch information is provided.

    0000083
    102 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13405 Arbitrary PHP Code Execution in Royal Addons for Elementor WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13405

    Post summary

    A new vulnerability (CVE-2026-13405) affecting Royal Addons for Elementor is announced, describing arbitrary PHP code execution; details are linked via the provided URL.

    00000108
    4.1K followersView on X

Explore more