Impact
The Royal Addons for Elementor plugin fails to validate certain widget settings before inserting them into an HTML attribute. This lack of sanitization allows a user with at least the Contributor role to inject arbitrary script code. When a post or page containing the affected widget is viewed, the malicious script runs in the browser of any user who sees the content, enabling theft of credentials, session cookies or delivery of phishing attacks.
Affected Systems
The flaw exists in Royal Addons for Elementor for WordPress versions prior to 1.7.1066. Sites hosting any of those plugin releases that include the Image Accordion widget with custom effect settings are vulnerable. All WordPress installations that deploy the known plugin and provide Contributor or higher level access are at risk.
Risk and Exploitability
Because the vulnerability requires the attacker to have Contributor-level access, the exploitability is limited to users who can edit the widget, yet the impact when successful is equivalent to a stored Cross‑Site Scripting on the site. No CVSS score is provided, and the EPSS is not available, but stored XSS is generally regarded as severe. The vulnerability is not listed in the CISA KEV catalog, so currently no publicly known exploitation campaign is documented, but the risk remains significant until the plugin is updated.
OpenCVE Enrichment