Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-862 |
Wed, 26 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts. | |
| Title | Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_init | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-26T14:43:10.829Z
Reserved: 2026-06-26T08:53:03.681Z
Link: CVE-2026-13404
Updated: 2026-08-26T14:40:49.147Z
Status : Deferred
Published: 2026-08-26T06:16:24.593
Modified: 2026-08-26T16:30:52.723
Link: CVE-2026-13404
No data.
OpenCVE Enrichment
Updated: 2026-08-26T08:00:03Z