Impact
King Addons for Elementor before version 51.1.77 contains a flaw where a widget display‑style setting is incorporated directly into an HTML attribute without escaping. A user who holds Contributor level permissions or higher can inject arbitrary JavaScript into that setting. Once stored, the injected script runs in the browsers of every visitor to the page, including users who are logged in as administrators.
Affected Systems
The vulnerability affects the King Addons for Elementor WordPress plugin in all releases prior to 51.1.77. It is specifically triggered by the Magazine Grid widget used in page layouts and is limited to that plugin only.
Risk and Exploitability
The EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw enables execution of arbitrary script in the context of all site visitors, the potential impact is high. An attacker with Contributor access can embed scripts that run on every page view, which can be used to hijack sessions, exfiltrate data, or deliver additional malicious payloads to users of the site.
OpenCVE Enrichment