Stored Cross-Site Scripting in Royal Addons for Elementor Plugin by WordPress
CVE-2026-5159
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-5159?
The Royal Addons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities through the 'instagram_follow_text' setting in the Instagram Feed widget. This issue arises from inadequate input sanitization and output escaping in all versions up to and including 1.7.1056. Authenticated attackers with Contributor-level access and higher can exploit this vulnerability to inject arbitrary web scripts into web pages. The injected scripts will execute whenever a user visits the modified page. Exploitation requires prior configuration of the Instagram Feed widget with a valid Instagram access token.
Affected Version(s)
Royal Addons for Elementor β Addons and Templates Kit for Elementor 0 <= 1.7.1056