
CVE-2026-5428 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up … https://www.cve.org/CVERecord?id=CVE-2026-5428
Post summary
The post announces a stored XSS vulnerability (CVE‑2026‑5428) in the Royal Elementor Addons WordPress plugin, noting that image captions in the Image Grid/Slider/Carousel widget are exploitable. No exploitation, PoC, or patch information is provided.

