CVE Database /
CVE-2026-5159
CVE · Medium
CVE-2026-5159 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-5159
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.7.1057
|
1.7.1057 |
2026-05-04 |
—
|
CVE-2026-5159
A security flaw exists within Royal Addons for Elementor plugin's Instagram Feed widget due to inadequate handling of user input, specifically in the 'instagram_follow_text' setting. This weakness allows authenticated users with Contributor-level permissions or higher to inject malicious scripts that will be executed when a page is accessed by another user, provided an administrator has previously set up the widget with valid Instagram credentials for the site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings