Impact
The Royal Elementor Addons plugin for WordPress, prior to version 1.7.1065, fails to validate a widget setting that is used to construct an HTML tag. This omission allows users who hold the Contributor role or higher to inject malicious JavaScript into the plugin’s Icon Box widget, resulting in a stored Cross‑Site Scripting vulnerability that can be executed whenever affected pages are viewed. The flaw can lead to session hijacking, credential theft, or defacement across all users who load the compromised content.
Affected Systems
The affected product is the Royal Elementor Addons for WordPress, provided by Royal Addons for Elementor. Any installation running a version earlier than 1.7.1065 is vulnerable, regardless of the site’s configuration or content volume.
Risk and Exploitability
The absence of input validation makes the attack vector straightforward: a Contributor can embed JavaScript payloads via the widget’s settings, which are persisted to the database and rendered in subsequent page loads. With an EPSS score of 0.00152 (0.15%) and the vulnerability not yet in the KEV catalog, the CVSS score of 5.4 indicates moderate severity for this stored XSS flaw, and the fact that Contributors are commonly present on many sites implies a significant risk. Attackers who can gain Contributor access, whether legitimately or through credential compromise, can exploit the flaw to hijack user sessions or disseminate malware.
OpenCVE Enrichment