Impact
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to stored cross‑site scripting via the Woo Grid widget in all releases up to and including version 1.7.1012. The flaw stems from insufficient input sanitization and output escaping, allowing an authenticated user with Contributor or higher privileges to inject arbitrary JavaScript that executes whenever a user visits a page containing the injected content. This can lead to cookie theft, session hijacking, defacement, and execution of other malicious payloads, and the weakness is classified as CWE‑79.
Affected Systems
The affected system is the Royal Elementor Addons and Templates WordPress plugin by wproyal. All releases from the initial launch up to and including version 1.7.1012 are impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating medium severity, and an EPSS score of less than 1 percent, showing a low likelihood of exploitation at present. It is not listed in the CISA Known Exploited Vulnerabilities catalogue. An attacker would need authenticated access with at least Contributor rights in the WordPress installation; with those privileges, they can inject scripts that run for any visitor to the affected page, enabling phishing, defacement, or persistence.
OpenCVE Enrichment
EUVD