Impact
King Addons for Elementor before version 51.1.77 contains a flaw where a widget display‑style setting is incorporated directly into an HTML attribute without escaping. A user who holds Contributor level permissions or higher can inject arbitrary JavaScript into that setting. Once stored, the injected script runs in the browsers of every visitor to the page, including users who are logged in as administrators.
Affected Systems
The vulnerability affects the King Addons for Elementor WordPress plugin in all releases prior to 51.1.77. It is specifically triggered by the Magazine Grid widget used in page layouts and is limited to that plugin only.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the flaw allows execution of arbitrary script in the context of all site visitors, the potential impact remains high. An attacker with Contributor access can embed scripts that run on every page view, which can be used to hijack sessions, exfiltrate data, or deliver additional malicious payloads to visitors.
OpenCVE Enrichment