CyberRota Analysis
AI-GeneratedThe Royal Addons for Elementor plugin for WordPress prior to version 1.7.1066 is vulnerable due to insufficient validation of widget settings, potentially enabling users with Contributor roles and higher to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability poses a medium risk as it can lead to unauthorized script execution within the context of the affected site. WordPress site administrators, particularly those using this plugin, should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.