Impact
The vulnerability allows a contributor or higher level user to import template content into a page without performing an object‑level authorization check. By including malicious JavaScript in a widget setting that is output without escaping, an attacker can create a stored XSS payload that executes in the browsers of any users who view the affected page.
Affected Systems
King Addons for Elementor, WordPress plugin versions earlier than 51.1.81. Any site running the plugin in a vulnerable version is affected.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of known exploitation. The attack vector requires only contributor‑level access, which many sites grant; an attacker could use a compromised contributor account or social engineering to perform the import. Once the payload is injected it executes in the context of any user viewing the page, potentially leading to session hijacking or credential theft.
OpenCVE Enrichment