All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-19217
MEDIUMpublished 2026-08-12 06:21 UTC · 21 hours ago · modified 2026-08-12 17:17 UTC
5.4
CVSS / 10
// description
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
// weaknesses (CWE)
- CWE-79