The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later executed, allowing users with the manage_options capability (and, on WordPress Multisite, non-super subsite administrators who do not otherwise hold code-execution capabilities) to execute arbitrary PHP code.
We have discovered 69,726 live websites that are affected by CVE-2026-13405.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 69,726 live websites (100% of Royal Elementor Addons install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 156 versions ( 99% of all versions) |
| 14,914 websites | |
| 7,439 websites | |
| 5,900 websites | |
| 5,634 websites | |
| 3,892 websites | |
| 3,691 websites | |
| 2,399 websites | |
| 2,333 websites | |
| 2,289 websites | |
| 1,427 websites |
| .com | 27,659 websites |
| .com.br | 5,148 websites |
| .de | 4,244 websites |
| .org | 3,017 websites |
| .fr | 2,868 websites |
| .it | 2,702 websites |
| .net | 1,292 websites |
| .co.uk | 1,206 websites |
| .pl | 1,098 websites |
| .nl | 1,032 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| *******.**.uk | *,*** | ||
| *********************.fr | **,*** | ||
| *********.gr | **,*** | ||
| ******.com | **,*** | ||
| ********.no | **,*** | ||
| ******.cc | **,*** | ||
| *******************.org | **,*** | ||
| ****************.***.ar | **,*** | ||
| *********.net | **,*** |
FAQ