Stored Cross-Site Scripting Vulnerability in Royal Elementor Addons for WordPress
CVE-2026-5428
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 April 2026
What is CVE-2026-5428?
The Royal Elementor Addons plugin for WordPress contains a vulnerability that allows authenticated users with Author access or higher to exploit Stored Cross-Site Scripting. This occurs through insufficient output escaping in the rendering process of image captions within the Image Grid/Slider/Carousel widget. By utilizing the wp_kses_post() function instead of the more appropriate esc_attr(), attackers can inject malicious scripts into the media grid widgets. These scripts will execute whenever a user views a page featuring the compromised images, potentially leading to unauthorized access or data exposure.
Affected Version(s)
Royal Addons for Elementor β Addons and Templates Kit for Elementor 0 <= 1.7.1056