Impact
Unauthenticated Insecure Direct Object References in the King Addons for Elementor plugin allow an attacker to request arbitrary resources by manipulating identifiers, enabling the disclosure of protected data such as settings, content blocks, or user‑generated content without authentication. This flaw does not grant direct code execution but can expose confidential information that could facilitate additional attacks.
Affected Systems
The vulnerability affects WordPress sites that have King Addons for Elementor version 51.1.81 or earlier installed. The plugin, provided by KingAddons.com, is used to extend Elementor functionality. Because the flaw is present in all editions of those releases, any WordPress installation deploying the plugin within that version range is susceptible.
Risk and Exploitability
The CVSS score of 5.3 classifies it as medium severity, and the EPSS score is currently unavailable, indicating no recent exploitation data is known. Since the flaw is exploitable without authentication, an attacker can trigger it from any network connection that reaches the WordPress instance. The vulnerability is not listed in the CISA KEV catalog, but administrators should elevate it to their risk posture due to its potential to reveal sensitive content. Promptly applying the vendor’s patch to version 51.1.82 or later mitigates the issue.
OpenCVE Enrichment