Impact
The Royal Elementor Addons plugin contains a stored XSS flaw caused by improper neutralization of user input when generating web pages. An attacker can inject malicious scripts that will execute in the browsers of users who view any page that incorporates the affected plugin. While the description does not detail further consequences, executing arbitrary scripts can compromise confidentiality, integrity, or availability of user sessions or lead to site defacement.
Affected Systems
WordPress installations that use the Royal Elementor Addons plugin version 1.7.1017 or earlier are vulnerable. The affected product is named Royal Elementor Addons; no specific WordPress core versions are noted, so any WordPress site running the plugin in the vulnerable version range is at risk.
Risk and Exploitability
The CVSS base score of 6.5 classifies the vulnerability as medium severity, and the EPSS score of less than 1% indicates a low predicted exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is low-privileged web-based; an attacker would need to supply malicious input that the plugin stores and later renders without proper sanitization, typically via a form or content field available to site visitors.
OpenCVE Enrichment
EUVD