Impact
The Royal Addons for Elementor plugin contains a stored cross‑site scripting flaw in the instagram_follow_text setting of its Instagram Feed widget. The plugin does not properly sanitize or escape user input, allowing malicious code to be stored and later rendered when any visitor loads a page containing the widget.
Affected Systems
All installations of Royal Addons for Elementor – Addons and Templates Kit for Elementor, vendor wproyal, up to and including version 1.7.1056. Any WordPress site that uses the Instagram Feed widget is affected.
Risk and Exploitability
The CVSS base score is 6.4, indicating moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with Contributor level or higher, typically granted to users who can contribute content. Once authenticated, an attacker can inject scripts that execute for every site visitor who views the affected page, making the attack practical in environments where contributor permissions are not tightly controlled.
OpenCVE Enrichment