Stored Cross-Site Scripting Vulnerability in Royal Elementor Addons for WordPress
CVE-2026-6504

6.4MEDIUM

What is CVE-2026-6504?

The Royal Elementor Addons and Templates plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks due to inadequate input sanitization and output escaping, specifically through the 'title_tag' parameter. This vulnerability allows authenticated users with Contributor-level access or higher to inject malicious web scripts. These scripts can execute on pages whenever a user accesses an injected page, posing significant security risks to both the application and its users. This issue affects all plugin versions leading up to 1.7.1058, making it essential for site administrators to implement the latest security updates.

Affected Version(s)

Royal Addons for Elementor – Addons and Templates Kit for Elementor 0 <= 1.7.1058

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Romain Deperne
.