Description
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Royal Addons for Elementor WordPress plugin versions prior to 1.7.1066 fails to enforce a capability or nonce check before furnishing taxonomy term data for any taxonomy specified by the caller. Consequently, unauthenticated users can retrieve the names and IDs of terms belonging to non‑public taxonomies. This flaw does not allow code execution, but it enables an attacker to discover internal taxonomy structures, which could aid in policy enumeration or further targeted attacks. The weakness is an improper access control issue, as the plugin does not restrict the data to authenticated or privileged users.

Affected Systems

WordPress sites running the "Royal Addons for Elementor" plugin, any version earlier than 1.7.1066. The vendor is listed as Unknown:Royal Addons for Elementor. No additional product or version details are supplied beyond the vulnerability threshold of 1.7.1066.

Risk and Exploitability

The CVSS score is not publicly available, and the EPSS score is not reported, so the precise risk quantification is unknown, but the vulnerability is exploitable by anyone who can access the WordPress installation externally. Because it requires no authentication or special privileges, the attack vector is straightforward: an unauthenticated HTTP request to the plugin’s taxonomy endpoint. The vulnerability is not currently tracked in the CISA KEV catalog, indicating no known widespread exploitation at this time.

Generated by OpenCVE AI on August 26, 2026 at 07:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Royal Addons for Elementor plugin to version 1.7.1066 or a later release that includes the access‑control fix.
  • If an upgrade cannot be performed immediately, block or delete the plugin’s taxonomy‑term API endpoint by disabling the plugin or restricting access with a security plugin or custom .htaccess rule so that only authenticated users can reach it.
  • Implement network or application‑layer filtering to deny unauthenticated requests to any endpoint that could expose taxonomy data, such as restricting access to the plugin’s REST routes or adding role‑based access control to these routes.

Generated by OpenCVE AI on August 26, 2026 at 07:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.
Title Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T06:00:18.287Z

Reserved: 2026-06-26T08:53:17.566Z

Link: CVE-2026-13406

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:45:02Z

Weaknesses