Impact
The King Addons for Elementor plugin, in versions prior to 51.1.81, contains a flaw in the kng_maintenance_page shortcode that does not perform capability, post‑status, or password checks before rendering a user‑supplied post. As a result, users with at least Contributor level privileges can view the content of private, draft, pending, and password‑protected posts that they are not authorized to access, exposing confidential post data to unauthorised readers.
Affected Systems
WordPress sites that have the King Addons for Elementor plugin installed at a version lower than 51.1.81. Every user role above Contributor—including editors and administrators—may exploit the flaw; site owners using older versions of the plugin are therefore at risk.
Risk and Exploitability
The CVSS score of 2.7 indicates a low overall severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The exploitation pathway involves deploying the vulnerable shortcode within a post or page that a Contributor can edit; the lack of validation allows the post’s private content to be rendered to the contributor’s browser. This attack requires only ordinary WordPress authoring permissions and can be carried out without network-level privileges, resulting in private content disclosure. Based on the description, the likely attack vector is through the web interface by creating or editing content that includes the shortcode.
OpenCVE Enrichment