CVE ID : CVE-2026-13402 Published : July 17, 2026, 6 a.m. | 59minutes ago Description : The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they…
| CVE ID | CVE-2026-13402 |
| Vendor | Unknown Vendor |
| Affected Product | Unknown Product |
| Vulnerability Type | Vulnerability |
| CVSS Score | 9.1 (CRITICAL) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | Pending Vendor Disclosure |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex) |
CVE ID : CVE-2026-13402
Published : July 17, 2026, 6 a.m. | 59minutes ago
Description : The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.
Severity: 0.0 | NA
Visit the link for more details, suc
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.