Description
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Royal Addons for Elementor plugin fails to validate certain widget settings before inserting them into an HTML attribute. This lack of sanitization allows a user with at least the Contributor role to inject arbitrary script code. When a post or page containing the affected widget is viewed, the malicious script runs in the browser of any user who sees the content, enabling theft of credentials, session cookies or delivery of phishing attacks.

Affected Systems

The flaw exists in Royal Addons for Elementor for WordPress versions prior to 1.7.1066. Sites hosting any of those plugin releases that include the Image Accordion widget with custom effect settings are vulnerable. All WordPress installations that deploy the known plugin and provide Contributor or higher level access are at risk.

Risk and Exploitability

Because the vulnerability requires the attacker to have Contributor-level access, the exploitability is limited to users who can edit the widget, yet the impact when successful is equivalent to a stored Cross‑Site Scripting on the site. No CVSS score is provided, and the EPSS is not available, but stored XSS is generally regarded as severe. The vulnerability is not listed in the CISA KEV catalog, so currently no publicly known exploitation campaign is documented, but the risk remains significant until the plugin is updated.

Generated by OpenCVE AI on August 26, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Royal Addons for Elementor to version 1.7.1066 or newer.
  • If an upgrade is not immediately possible, disable the Image Accordion widget or uninstall the Royal Addons for Elementor plugin entirely from the site.
  • Limit the number of users with Contributor or higher permissions, and consider removing contributor accounts that are unnecessary to the site’s operation.

Generated by OpenCVE AI on August 26, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 26 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Title Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect Settings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-26T14:43:09.512Z

Reserved: 2026-08-07T09:09:00.232Z

Link: CVE-2026-19226

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')