Junglewise Threat Intelligence

CVE-2026-0664: WP Royal Royal Addons for Elementor stored XSS in button_text

CVE-2026-0664 · Severity: medium · CVSS 6.4 · Published 2026-04-04

Vendors: WP Royal.

Executive brief

Royal Addons for Elementor is a popular WordPress plugin used to enhance website design and functionality. A security flaw allows users with basic contributor permissions to inject malicious scripts into website pages. These scripts execute automatically when other visitors or administrators view the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'button_text' parameter within the Form Builder module. An authenticated attacker with contributor-level access or higher can inject arbitrary web scripts into a page. Because the input is stored in the database and later rendered without proper security filtering, the script executes in the browser of any user who visits the compromised page. This vulnerability is tracked as CVE-2026-0664 and is addressed in version 1.7.1050.

Affected products

  • WP Royal Royal Addons for Elementor <= 1.7.1049

Timeline

  • 2026-04-04: disclosed
  • 2026-04-04: advisory

References