Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 26 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies. | |
| Title | Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-26T14:36:36.786Z
Reserved: 2026-06-26T08:53:17.566Z
Link: CVE-2026-13406
Updated: 2026-08-26T14:36:31.203Z
Status : Deferred
Published: 2026-08-26T06:16:24.700
Modified: 2026-08-26T16:30:52.723
Link: CVE-2026-13406
No data.
OpenCVE Enrichment
Updated: 2026-08-26T07:45:02Z