HIGHCVE-2026-28135Published Modified CNA Patchstack
CVE-2026-28135: WordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerability
Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1052.
Metrics
- CVSS v3.1
- 8.2
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
Affected packages
- WP Royal / Royal Elementor Addons≤ 1.7.1052
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:LReferences