Impact
Royal Addons for Elementor before version 1.7.1066 writes custom widget markup to a file without proper sanitisation. When that file is later executed by WordPress, an attacker who can manage options has the ability to inject and run arbitrary PHP code, effectively compromising the host environment. This flaw gives an authorised user the entire power of local code execution on the affected site.
Affected Systems
WordPress sites running the Royal Addons for Elementor plugin with any version earlier than 1.7.1066. The vulnerability is exploitable for users who possess the manage_options capability, and on multisite installations it also applies to non‑super subsite administrators who normally lack full code execution rights.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The flaw is not currently listed in CISA's KEV catalog. Exploitation requires administrative level privileges, so the attack vector is local within an authorised user context rather than external network access.
OpenCVE Enrichment