CVE-2026-5428 | wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress Carousel Widget render_post_thumbnail cross site scripting
A vulnerability has been found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress and classified as problematic. This impacts the function render_post_thumbnail of the component Carousel Widget. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-5428. The attack may be initiated remotely. There is no available exploit.