CVE · Medium

CVE-2026-5162 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5162 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.7.1057 1.7.1057 2026-04-16

CVE-2026-5162

A Stored Cross-Site Scripting vulnerability exists within the Royal Addons for Elementor plugin's Instagram Feed widget due to inadequate handling of input data. Specifically, the 'instagram_follow_text' setting is susceptible to malicious injection, allowing authenticated users with Contributor-level access or higher to embed arbitrary scripts that will run when accessed by other users. This issue affects all versions up to and including 1.7.1056.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.