
CVE-2026-0664 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1… https://www.cve.org/CVERecord?id=CVE-2026-0664
Post summary
The Royal Addons for Elementor plugin is vulnerable to Stored XSS via the 'button_text' parameter (CVE‑2026‑0664). The post does not provide a PoC, exploit tool, or patch information.


