rootpwn

medium · CVSS v3 6.5

CVE-2026-84903

The King Addons for Elementor plugin for WordPress fails to validate user capabilities, post statuses, or passwords before rendering post co

Overview

The King Addons for Elementor plugin for WordPress fails to validate user capabilities, post statuses, or passwords before rendering post content. This allows authenticated users with low privileges, such as contributors, to bypass authorization controls and read unauthorized restricted posts.

Description

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.

Impact

This vulnerability compromises the confidentiality of sensitive information by exposing private, draft, pending, and password-protected posts to unauthorized low-privileged users. The impact is restricted to data disclosure without direct system compromise or data modification capabilities. WordPress administrators and site owners are primarily affected.

Remediation

Update the King Addons for Elementor plugin to version 51.1.81 or later where proper authorization and access checks are implemented. Continuously monitor user roles and restrict untrusted accounts from obtaining Contributor-level access if not required.

Risk context

The vulnerability is rated as medium severity with a CVSS v3 score of 6.5. EPSS data is not currently available, but defenders should prioritize patching to prevent internal information disclosure.

Affected products

  • King Addons for Elementor WordPress plugin < 51.1.81

Scores

Severity
medium
CVSS v2
4
CVSS v3
6.5
CVSS v4
EPSS

wordpress plugin authorization-bypass information-disclosure elementor access-control

← All CVEs