CVE-2026-84902 Details
Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.
A stored cross-site scripting vulnerability has been identified in the King Addons for Elementor WordPress plugin, affecting versions prior to 51.1.81. The issue arises because the plugin does not implement proper authorization checks when importing template content into pages. This flaw allows users with contributor-level access and above to overwrite Elementor content on any post or page, including those belonging to administrators. Additionally, it enables the injection of JavaScript through a widget setting, which is rendered without proper escaping. As a result, the injected script executes in the session of any user who views the affected page.
Users are advised to update the King Addons for Elementor WordPress plugin to version 51.1.81 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/4afc5f30-8b30-4e77-9bd7-91c25065bb54/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| King Addons | < 51.1.81 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion