high · CVSS v3 7.1
CVE-2026-84904
King Addons for Elementor WordPress plugin before version 51.1.81 lacks proper object-level authorization for specific image optimization ac
Overview
King Addons for Elementor WordPress plugin before version 51.1.81 lacks proper object-level authorization for specific image optimization actions. This allows authenticated users with author-level privileges to perform unauthorized manipulations on media objects belonging to other users. Consequently, attackers can disclose absolute file paths, overwrite file bytes, and re-reference media site-wide.
Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
Impact
This vulnerability impacts the Confidentiality and Integrity of media objects within the WordPress site. An authenticated attacker with low privileges (author level) can access sensitive server paths, alter administrative files, and manipulate media assets. Administrators and other users with media ownership are directly affected by unauthorized modifications.
Remediation
Update the King Addons for Elementor plugin to version 51.1.81 or later where the missing authorization checks are properly implemented. Regularly audit user role assignments to ensure principle of least privilege is enforced.
Risk context
The vulnerability carries a CVSS v3 score of 7.1, indicating a high risk level for affected WordPress installations. Immediate patching is recommended to prevent unauthorized administrative media manipulation.
Affected products
- King Addons for Elementor
Scores
- Severity
- high
- CVSS v2
- 5.5
- CVSS v3
- 7.1
- CVSS v4
- —
- EPSS
- —