Stored Cross-Site Scripting Vulnerability in Royal Elementor Addons for WordPress
CVE-2026-6504
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2026-6504?
The Royal Elementor Addons and Templates plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks due to inadequate input sanitization and output escaping, specifically through the 'title_tag' parameter. This vulnerability allows authenticated users with Contributor-level access or higher to inject malicious web scripts. These scripts can execute on pages whenever a user accesses an injected page, posing significant security risks to both the application and its users. This issue affects all plugin versions leading up to 1.7.1058, making it essential for site administrators to implement the latest security updates.
Affected Version(s)
Royal Addons for Elementor β Addons and Templates Kit for Elementor 0 <= 1.7.1058