rootpwn

medium · CVSS v3 5.4

CVE-2026-84902

The King Addons for Elementor WordPress plugin (v<51.1.81) lacks object-level authorization during template import, allowing contributor-lev

Overview

The King Addons for Elementor WordPress plugin (v<51.1.81) lacks object-level authorization during template import, allowing contributor-level users to overwrite any post or page content. This flaw also permits injection of unescaped JavaScript via widget settings, leading to stored XSS that affects all visitors to the compromised page. The vulnerability can compromise confidentiality, integrity, and availability of site content and user sessions.

Description

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.

Impact

Confidentiality: attackers can read or modify page content. Integrity: arbitrary content replacement and script injection alter page behavior. Availability: repeated XSS can degrade user experience. The flaw primarily impacts site administrators, editors, and any users who view affected pages.

Remediation

Update King Addons for Elementor to version 51.1.81 or later. If update is not possible, restrict contributor-level access or disable the template import feature. Additionally, sanitize widget settings and enforce proper escaping on output. Monitor site logs for unauthorized content changes.

Risk context

Medium severity (CVSS 5.4). No EPSS data available. The vulnerability is exploitable by users with contributor-level access, making it a moderate risk that should be addressed promptly.

Affected products

  • King Addons for Elementor
  • WordPress
  • Elementor plugin

Scores

Severity
medium
CVSS v2
3.5
CVSS v3
5.4
CVSS v4
EPSS

wordpress plugin xss authorization content-manipulation king-addons elementor

← All CVEs