CVE-2026-0664Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-04: 2Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-10: 1Technical Details · 2026-04-04: 204-0404-10
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-042
Disclosure2
2026-04-101
PoC1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-0664 The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1… https://www.cve.org/CVERecord?id=CVE-2026-0664

    Post summary

    The Royal Addons for Elementor plugin is vulnerable to Stored XSS via the 'button_text' parameter (CVE‑2026‑0664). The post does not provide a PoC, exploit tool, or patch information.

    00010155
    57.0K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-0664-royal-elementor-addons-version-1-7-1049-medium-vulnerability-proof-of-concept CVE-2026-0664 #WordPress plugin #vulnerability royal-elementor-addons #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post shares a URL to a proof‑of‑concept for CVE-2026-0664, but does not provide an exploit tool, evidence of active exploitation, patch info, or detailed technical description.

    0000046
    6 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-0664 - Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass Intel Report: https://ift.tt/bkVP7Oz

    Post summary

    A new CVE (CVE-2026-0664) has been disclosed, affecting Royal Elementor Add‑ons up to 1.7.1049, enabling authenticated contributors to perform stored XSS via a REST API meta bypass.

    0000076
    281 followersView on X

Explore more