Description
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-12-13
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via Authenticated Contributor Access
Action: Immediate Patch
AI Analysis

Impact

The plugin allows full control over widget configurations. In versions up to and including 51.1.39 the widget attributes are taken from user input without proper sanitization or output escaping, permitting an authenticated contributor or higher to embed arbitrary JavaScript directly into the widget markup. When a visitor loads a page that contains the modified widget, the injected script executes in that visitor's browser, exposing the site to flash‑pharming, cookie theft, or malicious redirection. This vulnerability corresponds to CWE‑79 and delivers the attacker control over client‑side code while bypassing the site's content security mechanisms, thereby compromising confidentiality, integrity, and availability of the web interface for end users.

Affected Systems

All releases of the King Addons for Elementor WordPress plugin on the WordPress plugin repository through version 51.1.39 are affected. The vulnerability occurs in the plugin’s Pricing Slider, Pricing Calculator, and Image Accordion widgets, which are part of the King Addons for Elementor suite that offers more than 80 Elementor widgets, thousands of templates, and integrated WooCommerce enhancements.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium impact for an attacker who already has contributor rights on the WordPress installation. EPSS of less than 1% shows that, so far, the vulnerability has not seen widespread exploitation. It is not currently in the CISA KEV catalog. Because the flaw requires authenticated access, an attacker must first obtain contributor or higher privileges, after which the vulnerability can be leveraged by creating or editing a widget that contains malicious JavaScript. Once the page is viewed by other users, the injected script runs with the visitor’s browsing context, which can lead to session hijacking, defacement, or phishing. Hence the risk is moderately high for vulnerable installations that expose contributor‑level accounts to untrusted parties.

Generated by OpenCVE AI on April 21, 2026 at 00:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade King Addons for Elementor to version 51.1.40 or newer to fix the XSS flaw.
  • If an upgrade is not immediately feasible, disable or remove the Pricing Slider, Pricing Calculator, and Image Accordion widgets from the site to eliminate the attack surface.
  • Restrict contributor‑level or higher WordPress user roles until the patch is applied.
  • Implement a web application firewall rule that blocks suspicious XSS payloads from widget content.

Generated by OpenCVE AI on April 21, 2026 at 00:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Kingaddons
Kingaddons king Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Kingaddons
Kingaddons king Addons For Elementor
Wordpress
Wordpress wordpress

Sat, 13 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Kingaddons King Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:54:24.380Z

Reserved: 2025-07-21T14:56:56.963Z

Link: CVE-2025-7960

cve-icon Vulnrichment

Updated: 2025-12-15T15:42:58.129Z

cve-icon NVD

Status : Deferred

Published: 2025-12-13T16:16:55.643

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-7960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T01:00:12Z

Weaknesses