SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19226

MEDIUM · CVSS 6.8 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Royal Addons for Elementor plugin for WordPress prior to version 1.7.1066 is vulnerable due to insufficient validation of widget settings, potentially enabling users with Contributor roles and higher to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability poses a medium risk as it can lead to unauthorized script execution within the context of the affected site. WordPress site administrators, particularly those using this plugin, should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-19226
Severity
MEDIUM
CVSS
6.8
EPSS
0.32%
WordPress

Original NVD Description

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.