Stored Cross-Site Scripting in Royal Addons for Elementor Plugin by WordPress
CVE-2026-5159

6.4MEDIUM

What is CVE-2026-5159?

The Royal Addons for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities through the 'instagram_follow_text' setting in the Instagram Feed widget. This issue arises from inadequate input sanitization and output escaping in all versions up to and including 1.7.1056. Authenticated attackers with Contributor-level access and higher can exploit this vulnerability to inject arbitrary web scripts into web pages. The injected scripts will execute whenever a user visits the modified page. Exploitation requires prior configuration of the Instagram Feed widget with a valid Instagram access token.

Affected Version(s)

Royal Addons for Elementor – Addons and Templates Kit for Elementor 0 <= 1.7.1056

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Nam
.