CVE-2026-27421: WordPress Royal Elementor Addons plugin < 1.7.1053 - Cross Site Scripting (XSS) vulnerability
Published May 7, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.
This issue affects Royal Elementor Addons: from n/a before 1.7.1053.
Affected Software
1 affected component
WProyal Royal Elementor Addons<1.7.1053
Remediation
Information
Update the WordPress Royal Elementor Addons Plugin to the latest available version (at least 1.7.1053).
Event History
May 7, 2026
CVE Published
via MITRE·07:31 AM
Data Sourced
via MITRE·07:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27421?
CVE-2026-27421 has a moderate severity rating due to its potential for exploitation through stored XSS attacks.
2
How do I fix CVE-2026-27421?
To fix CVE-2026-27421, update the Royal Elementor Addons plugin to version 1.7.1054 or later.
3
What type of vulnerability is CVE-2026-27421?
CVE-2026-27421 is a Cross Site Scripting (XSS) vulnerability that allows stored XSS attacks.
4
Which versions of Royal Elementor Addons are affected by CVE-2026-27421?
Royal Elementor Addons versions prior to 1.7.1054 are affected by CVE-2026-27421.
5
What impact can CVE-2026-27421 have on my website?
CVE-2026-27421 can allow attackers to inject malicious scripts into your website, compromising user data and security.