Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84902 2 Kingaddons, Wordpress-extensions 2 King Addons For Elementor, King Addons For Elementor 2026-09-29 6.8 Medium
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.
CVE-2026-84903 2 Kingaddons, Wordpress-extensions 2 King Addons For Elementor, King Addons For Elementor 2026-09-29 2.7 Low
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.
CVE-2026-84904 2 Kingaddons, Wordpress-extensions 2 King Addons For Elementor, King Addons For Elementor 2026-09-29 3.8 Low
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.