CVE-2026-84902 PUBLISHED

King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import

Assigner: WPScan
Reserved: 02.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.

Product Status

Vendor Unknown
Product King Addons for Elementor
Versions Default: unaffected
  • affected from 0 to 51.1.81 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE