Executive brief
Royal Addons for Elementor is a popular WordPress plugin used to enhance website design and functionality. A security flaw allows users with basic contributor permissions to inject malicious scripts into website pages. These scripts execute automatically when other visitors or administrators view the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'button_text' parameter within the Form Builder module. An authenticated attacker with contributor-level access or higher can inject arbitrary web scripts into a page. Because the input is stored in the database and later rendered without proper security filtering, the script executes in the browser of any user who visits the compromised page. This vulnerability is tracked as CVE-2026-0664 and is addressed in version 1.7.1050.
Affected products
- WP Royal Royal Addons for Elementor <= 1.7.1049
Timeline
- 2026-04-04: disclosed
- 2026-04-04: advisory