medium · CVSS v3 6.5
CVE-2026-84903
The King Addons for Elementor plugin for WordPress fails to validate user capabilities, post statuses, or passwords before rendering post co
Overview
The King Addons for Elementor plugin for WordPress fails to validate user capabilities, post statuses, or passwords before rendering post content. This allows authenticated users with low privileges, such as contributors, to bypass authorization controls and read unauthorized restricted posts.
Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.
Impact
This vulnerability compromises the confidentiality of sensitive information by exposing private, draft, pending, and password-protected posts to unauthorized low-privileged users. The impact is restricted to data disclosure without direct system compromise or data modification capabilities. WordPress administrators and site owners are primarily affected.
Remediation
Update the King Addons for Elementor plugin to version 51.1.81 or later where proper authorization and access checks are implemented. Continuously monitor user roles and restrict untrusted accounts from obtaining Contributor-level access if not required.
Risk context
The vulnerability is rated as medium severity with a CVSS v3 score of 6.5. EPSS data is not currently available, but defenders should prioritize patching to prevent internal information disclosure.
Affected products
- King Addons for Elementor WordPress plugin < 51.1.81
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —