Junglewise Threat Intelligence

CVE-2026-13405: Royal Elementor Addons remote code execution in widget builder

CVE-2026-13405 · Severity: medium · CVSS 6.6 · Published 2026-08-20

Technologies: Royal Elementor Addons.

Executive brief

Royal Elementor Addons is a popular WordPress plugin that provides additional widgets for Elementor page builder. On WordPress Multisite installations, administrators of individual subsites can exploit improper sanitization in the widget builder to inject and execute arbitrary PHP code, compromising all sites on the network and the underlying server infrastructure.

Technical details

The plugin fails to properly sanitize user-supplied markup when custom widgets are created via the widget-builder REST endpoint before writing it to a PHP file that is later executed. The vulnerability exploits a single-pass str_replace() that strips PHP tags, allowing overlapping token sequences (e.g., "<<??=...??>>") to recombine into valid PHP short-echo blocks ("<?=...?>") that execute unconditionally. An attacker with manage_options capability (subsite administrator on Multisite) can craft a malicious widget, save it via an unauthenticated REST call using a wp-rest nonce, and trigger PHP execution by viewing any page containing that widget. This requires only WordPress Multisite and the plugin installed network-wide; no additional authentication beyond typical admin privileges is needed. The vulnerability was fixed in version 1.7.1066.

Affected products

  • Royal Elementor Addons Royal Elementor Addons before 1.7.1066

Timeline

  • 2026-08-18: disclosed
  • 2026-08-20: patched: Fixed in version 1.7.1066

References