CVE-2026-84904 PUBLISHED

King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer

Assigner: WPScan
Reserved: 02.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.

Product Status

Vendor Unknown
Product King Addons for Elementor
Versions Default: unaffected
  • affected from 51.1.56 to 51.1.81 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE