CVE-2026-5162 | wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress Instagram Feed Widget instagram_follow_text cross site scripting
A vulnerability was found in wproyal Royal Addons for Elementor Plugin up to 1.7.1056 on WordPress. It has been rated as problematic. This vulnerability affects the function instagram_follow_text of the component Instagram Feed Widget. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-5162. The attack is possible to be carried out remotely. No exploit exists.