Impact
This vulnerability allows attackers to exploit an improper neutralization of input during web page generation in the Royal Elementor Addons plugin, resulting in stored cross‑site scripting. An attacker can inject malicious JavaScript that will execute in the browsers of users who view affected content, potentially enabling session hijacking, credential theft, or defacement. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites that use the WP Royal: Royal Elementor Addons plugin version 1.3.977 or earlier are affected; any installation of this plugin that has not been updated beyond this version will be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies this vulnerability as moderate in severity. The EPSS score being less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit this vulnerability by creating or editing content that is stored by the plugin, with the malicious payload rendered to other users with no special authentication required.
OpenCVE Enrichment
EUVD