HomeCVE Intelligence › CVE-2026-13402
CVSS 9.1 CRITICAL Vulnerability

CVE-2026-13402: CVE-2026-13402 - Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Te…

CVE ID : CVE-2026-13402 Published : July 17, 2026, 6 a.m. | 59minutes ago Description : The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they…

9.1CVSS Score
CRITICALSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-13402
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.1 (CRITICAL)
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

CVE ID : CVE-2026-13402

Published : July 17, 2026, 6 a.m. | 59minutes ago

Description : The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.

Severity: 0.0 | NA

Visit the link for more details, suc

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-13402","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-13402 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence