THREAT OPS › Threat News › [NVD] CVE-2026-5428 (MEDIUM 6.4) — The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function,
[NVD] CVE-2026-5428 (MEDIUM 6.4) — The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function,
CVE-2026-5428 CVSS: 6.4 MEDIUM Published: 2026-04-24T06:16:08.643
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() fo
MITRE ATT&CK techniques
- Malicious ImageT1204.003
Indicators of compromise
- CVE-2026-5428cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5428