Executive brief
Royal Elementor Addons is a popular WordPress plugin that provides additional widgets for Elementor page builder. On WordPress Multisite installations, administrators of individual subsites can exploit improper sanitization in the widget builder to inject and execute arbitrary PHP code, compromising all sites on the network and the underlying server infrastructure.
Technical details
The plugin fails to properly sanitize user-supplied markup when custom widgets are created via the widget-builder REST endpoint before writing it to a PHP file that is later executed. The vulnerability exploits a single-pass str_replace() that strips PHP tags, allowing overlapping token sequences (e.g., "<<??=...??>>") to recombine into valid PHP short-echo blocks ("<?=...?>") that execute unconditionally. An attacker with manage_options capability (subsite administrator on Multisite) can craft a malicious widget, save it via an unauthenticated REST call using a wp-rest nonce, and trigger PHP execution by viewing any page containing that widget. This requires only WordPress Multisite and the plugin installed network-wide; no additional authentication beyond typical admin privileges is needed. The vulnerability was fixed in version 1.7.1066.
Affected products
- Royal Elementor Addons Royal Elementor Addons before 1.7.1066
Timeline
- 2026-08-18: disclosed
- 2026-08-20: patched: Fixed in version 1.7.1066