Executive brief
Royal Elementor Addons Pro is a popular extension for the WordPress Elementor page builder that adds advanced design widgets and features to websites. A security vulnerability in versions older than 1.7.1041 allows unauthenticated attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link, the attacker could steal session information, redirect users to malicious websites, or perform unauthorized actions on the site.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Royal Elementor Addons Pro due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized administrative actions, or website defacement. The issue is resolved in version 1.7.1041.
Affected products
- Royal Elementor Addons Royal Elementor Addons Pro < 1.7.1041
Timeline
- 2025-11-21: other: Reported by researcher mcdruid
- 2026-04-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date