Stored Cross-Site Scripting Vulnerability in Royal Addons for Elementor Plugin by WordPress
CVE-2026-19217
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-19217?
The Royal Addons for Elementor plugin for WordPress, prior to version 1.7.1065, contains a vulnerability that fails to adequately validate widget settings when generating HTML outputs. This oversight allows users with Contributor roles or higher to inject malicious scripts, facilitating Stored Cross-Site Scripting attacks. Malicious users could exploit this flaw to execute arbitrary scripts in the context of affected users, potentially leading to unauthorized data access or user sessions hijacking.
Affected Version(s)
Royal Addons for Elementor 0 < 1.7.1065
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.