Executive brief
The Royal Elementor Addons and Templates plugin for WordPress, which provides enhanced design tools for website builders, contains a security flaw. This vulnerability allows users with basic contributor-level access to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.
Technical details
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'title_tag' parameter. This vulnerability exists in multiple widgets, including the Posts Timeline and Video Playlist modules. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into the database. These scripts will then execute in the browser of any user who visits the affected page. The issue is addressed in versions following 1.7.1058.
Affected products
- WP Royal Royal Elementor Addons and Templates Up to, and including, 1.7.1058
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory
References
- https://plugins.trac.wordpress.org/changeset/3525351/royal-elementor-addons/trunk/modules/posts-timeline/widgets/wpr-posts-timeline.php
- https://plugins.trac.wordpress.org/changeset/3525351/royal-elementor-addons/trunk/modules/video-playlist/widgets/wpr-video-playlist.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ed86e902-7637-481d-9005-7025187ba200?source=cve