Description
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
Published: 2026-09-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

King Addons for Elementor before version 51.1.77 contains a flaw where a widget display‑style setting is incorporated directly into an HTML attribute without escaping. A user who holds Contributor level permissions or higher can inject arbitrary JavaScript into that setting. Once stored, the injected script runs in the browsers of every visitor to the page, including users who are logged in as administrators.

Affected Systems

The vulnerability affects the King Addons for Elementor WordPress plugin in all releases prior to 51.1.77. It is specifically triggered by the Magazine Grid widget used in page layouts and is limited to that plugin only.

Risk and Exploitability

The EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw enables execution of arbitrary script in the context of all site visitors, the potential impact is high. An attacker with Contributor access can embed scripts that run on every page view, which can be used to hijack sessions, exfiltrate data, or deliver additional malicious payloads to users of the site.

Generated by OpenCVE AI on September 5, 2026 at 09:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade King Addons for Elementor to version 51.1.77 or later.
  • If an immediate upgrade is not possible, remove or disable the Magazine Grid widget from all pages and restrict Contributor accounts from editing widgets that render user‑supplied input.
  • Apply a site‑wide Content Security Policy (CSP) or other XSS protection mechanisms to mitigate the impact of any remaining unsanitized content.

Generated by OpenCVE AI on September 5, 2026 at 09:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
Title King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:08.703Z

Reserved: 2026-09-02T15:06:42.525Z

Link: CVE-2026-84896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:13.940

Modified: 2026-09-05T07:17:13.940

Link: CVE-2026-84896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T09:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')