CVE · Medium

CVE-2026-5428 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5428 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1057 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.7.1057 1.7.1057 2026-04-23

CVE-2026-5428

The Royal Elementor Addons plugin for WordPress contains a vulnerability that allows attackers with Author-level access or higher to inject malicious code into image captions in the Image Grid/Slider/Carousel widget, which can then be executed when a user views the page containing the compromised image. This occurs because the plugin does not properly sanitize the image alt attribute, allowing attackers to inject arbitrary web scripts. As a result, authenticated attackers can inject malicious code that will execute whenever a user accesses a page displaying the malicious image.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.