Description
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce that allows unauthenticated access to the AJAX handler. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-05-05
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Royal Elementor Addons plugin is affected by a stored cross‑site scripting flaw in the wpr_update_form_action_meta AJAX handler. Because the 'status' parameter is not properly sanitized or escaped, and the associated nonce is publicly leaked, attackers can submit arbitrary HTML or JavaScript that is persisted in the site database. When a visitor opens a page that includes the stored value, the injected script runs in the victim’s browser, enabling cookie theft, session hijacking, defacement, or the execution of further malicious payloads. The weakness is identified as CWE‑79.

Affected Systems

The vulnerability exists in the Royal Addons for Elementor – Addons and Templates Kit for Elementor from the vendor wproyal. All releases up to and including version 1.7.1056 are affected. Users should verify the installed version and upgrade if necessary.

Risk and Exploitability

The CVSS score is 7.2, reflecting a high severity. The EPSS score is not available, but the fact that the nonce is publicly available removes authentication barriers, making exploitation straightforward for an unauthenticated attacker with internet access to the site. Although the flaw is not listed in the CISA KEV catalog, the stored nature of the payload means that once an attacker injects a malicious script, it will impact every user who visits the affected page. The attack vector is purely web‑based; no privileged access is required beyond the ability to trigger the AJAX call.

Generated by OpenCVE AI on May 5, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Royal Elementor Addons to a fixed version (1.7.1057 or newer).
  • If an update cannot be applied immediately, block or disable the wpr_update_form_action_meta AJAX endpoint for unauthenticated users, or restrict it via role‑based access controls.
  • Apply a web application firewall rule to block attempts to submit script tags or other XSS payloads to the plugin’s AJAX actions.

Generated by OpenCVE AI on May 5, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 05 May 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wproyal
Wproyal royal Addons For Elementor – Addons And Templates Kit For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wproyal
Wproyal royal Addons For Elementor – Addons And Templates Kit For Elementor

Tue, 05 May 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1.7.1056. This is due to insufficient input sanitization and output escaping, combined with a publicly leaked nonce that allows unauthenticated access to the AJAX handler. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wproyal Royal Addons For Elementor – Addons And Templates Kit For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-05T03:37:38.588Z

Reserved: 2026-03-25T11:13:17.868Z

Link: CVE-2026-4803

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-05T04:16:18.230

Modified: 2026-05-05T04:16:18.230

Link: CVE-2026-4803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-05T05:30:16Z

Weaknesses