CVE-2026-13405: Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manageoptions capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
An attacker needs the WordPress manage_options capability. In a WordPress Multisite deployment, a non-super administrator of a subsite may exploit it even if that account would not normally have code-execution capabilities.
What versions need remediation?
Royal Addons for Elementor versions before 1.7.1066 are affected. Update the plugin to version 1.7.1066 or later.
What is the impact of successful exploitation?
A qualifying user can cause arbitrary PHP code to be written to a file that is later executed, resulting in remote code execution.