PatchSiren

King Addons CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM King Addons CVE published 2026-09-05

CVE-2026-84896

The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators. This vulnerability has significant implications for WordPress installations wit [truncated]

MEDIUM King Addons CVE published 2026-08-02

CVE-2026-14841

The King Addons for Elementor WordPress plugin before version 51.1.76 does not properly escape user-supplied grid settings in an unauthenticated AJAX response. This allows for arbitrary JavaScript execution in the browser of a visitor loading a crafted page. The vulnerability is reportedly exploitable through a reflected XSS attack vector. Affected systems may be vulnerable to JavaScript execution attacks [truncated]

MEDIUM King Addons CVE published 2026-06-15

CVE-2026-48870

A Cross Site Scripting (XSS) vulnerability was discovered in the King Addons for Elementor plugin. This issue allows a subscriber to inject malicious scripts into the webpage, potentially leading to unauthorized actions or data theft. The vulnerability has been rated with a CVSS score of 6.5, indicating a medium severity level.