{"id":"CVE-2026-17585","title":"The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter","summary":"The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it po…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"wproyal","product":"Royal Addons for Elementor – Addons and Templates Kit for Elementor","affected":["royal_addons_for_elementor_addons_and_templates_kit_for_elementor <= 1.7.1066"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T19:17:15.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17585","references":[{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L115","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L155","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L23","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/plugin.php#L655","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L115","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L155","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L23","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/plugin.php#L655","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5eab79e6-cb47-4fe7-993a-e833bd6689f8?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"epss":0.00323,"epssPercentile":0.25556,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-14T18:30:32.543483Z"},"ingestedAt":"2026-09-14T15:23:07.480Z","slug":"CVE-2026-17585","body":"## Overview\n\nThe Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}