WP Vulnerability WatchVulnerability data as of September 12, 2026

Vulnerability alerts / September 11, 2026

Vulnerability in Royal Addons for Elementor – Addons and Templates Kit for Elementor — CVE-2026-17585

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
600,000+ sitesInstalls
1.7.1067Fixed in

What to do now

Update Royal Addons for Elementor – Addons and Templates Kit for Elementor to 1.7.1067 or later.

Affected versions

  • Everything up to and including 1.7.1066

Affected: Royal Addons for Elementor – Addons and Templates Kit for Elementor (plugin, royal-elementor-addons)

Check: The plugin on wordpress.org / Our record for Royal Addons for Elementor – Addons and Templates Kit for Elementor

What the vulnerability is

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/5eab79e6-cb47-4fe7-993a-e833bd6689f8
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts