CVE-2026-13402
MEDIUMRoyal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
Title source: cnaDescription
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/1a7a9159-0e85-43c4-b1ab-7ea37a4f2d95/
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
None/Royal Addons for Elementor
< 1.7.1063
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026