rootpwn

high · CVSS v3 7.1

CVE-2026-84904

King Addons for Elementor WordPress plugin before version 51.1.81 lacks proper object-level authorization for specific image optimization ac

Overview

King Addons for Elementor WordPress plugin before version 51.1.81 lacks proper object-level authorization for specific image optimization actions. This allows authenticated users with author-level privileges to perform unauthorized manipulations on media objects belonging to other users. Consequently, attackers can disclose absolute file paths, overwrite file bytes, and re-reference media site-wide.

Description

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.

Impact

This vulnerability impacts the Confidentiality and Integrity of media objects within the WordPress site. An authenticated attacker with low privileges (author level) can access sensitive server paths, alter administrative files, and manipulate media assets. Administrators and other users with media ownership are directly affected by unauthorized modifications.

Remediation

Update the King Addons for Elementor plugin to version 51.1.81 or later where the missing authorization checks are properly implemented. Regularly audit user role assignments to ensure principle of least privilege is enforced.

Risk context

The vulnerability carries a CVSS v3 score of 7.1, indicating a high risk level for affected WordPress installations. Immediate patching is recommended to prevent unauthorized administrative media manipulation.

Affected products

  • King Addons for Elementor

Scores

Severity
high
CVSS v2
5.5
CVSS v3
7.1
CVSS v4
EPSS

wordpress plugin authorization insecure-direct-object-references file-overwrite path-disclosure

← All CVEs