Royal Elementor Addons and Templates
cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:wordpress:*:*
- <= 1.7.1017
A stored cross-site scripting vulnerability has been identified in the Royal Elementor Addons and Templates plugin for WordPress, affecting all versions up to and including 1.7.1017. The issue arises in the Countdown widget, specifically through the display_message_text parameter, due to inadequate input sanitization and output escaping. This vulnerability allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages, which are executed when users access the compromised page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
To reproduce this vulnerability, an authenticated user with Contributor-level access or higher can inject a script into the Countdown widget's message parameter. The injected script will be executed when the page is viewed.
Users are advised to update the Royal Elementor Addons and Templates WordPress plugin to version 1.7.1018 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.