CVE-2026-19217: Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget
Published Aug 12, 2026
·Updated
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Royal Elementor Addons Royal Addons for Elementor<1.7.1065
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:21 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-19217?
CVE-2026-19217 has a risk rating of 32, indicating a moderate severity level.
2
How do I fix CVE-2026-19217?
To mitigate CVE-2026-19217, update the Royal Elementor Addons plugin to version 1.7.1065 or later.
3
Who is affected by CVE-2026-19217?
CVE-2026-19217 affects users with Contributor roles and above using versions of Royal Elementor Addons prior to 1.7.1065.
4
What type of vulnerability is CVE-2026-19217?
CVE-2026-19217 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
What is the impact of CVE-2026-19217?
If exploited, CVE-2026-19217 can allow attackers to execute malicious scripts in the context of users’ browsers.