CVE-2026-5159 | wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress Instagram Feed Widget instagram_follow_text cross site scripting (EUVD-2026-27189)
A vulnerability has been found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress and classified as problematic. Impacted is the function instagram_follow_text of the component Instagram Feed Widget. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-5159. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.