
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28135 is an "Inclusion of Functionality from Untrusted Control Sphere" vulnerability (CWE-829) in the WP Royal Royal Elementor Addons WordPress plugin. It allows unauthenticated remote attackers to access functionality not properly constrained by ACLs. The vulnerability affects Royal Elementor Addons versions up to and including 1.7.1052 (initially disclosed as affecting up to 1.7.1049, later updated). It was published on March 5, 2026, by Patchstack, and carries a CVSS v3.1 base score of 8.2 (High) (Patchstack).
The vulnerability is classified under CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning the plugin incorporates or references functionality from an untrusted source without adequate access controls. This allows attackers to invoke plugin functionality that should be restricted, bypassing ACL enforcement. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable remotely. An estimated secondary classification of CWE-434 (Unrestricted Upload of File with Dangerous Type) has also been associated with this vulnerability by Feedly's analysis, suggesting the ACL bypass may facilitate unauthorized file operations (Patchstack).
Successful exploitation can result in high integrity impact and moderate availability impact on the affected WordPress site, with no direct confidentiality impact per the Patchstack CVSS assessment. An unauthenticated attacker could manipulate or corrupt site content, potentially deface the site or disrupt its availability. The CISA-ADP scoring alternatively emphasizes high availability impact and low integrity impact, suggesting the vulnerability may also be leveraged to cause denial-of-service conditions. The scope is limited to the affected WordPress installation, but compromise of site integrity could facilitate further attacks against site visitors (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2026-28135 as of the available data. The EPSS score is very low at approximately 0.018%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Patchstack).
Users should update the Royal Elementor Addons plugin to a version beyond 1.7.1052, as all versions up to and including 1.7.1052 are affected. The vulnerability was reported by Patchstack, and site administrators should monitor the official WordPress plugin repository or the WP Royal vendor page for a patched release. As an interim measure, consider disabling the plugin until a fix is confirmed, or restrict access to the WordPress admin and plugin functionality via firewall rules or web application firewall (WAF) rules (Patchstack).
Sucuri included CVE-2026-28135 in their March 2026 vulnerability patch roundup, indicating it received attention in the WordPress security community (Sucuri Blog). No significant vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."