Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.
Published: 2026-09-18
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Private Content Disclosure
Action: Update Plugin
AI Analysis

Impact

The King Addons for Elementor plugin, in versions prior to 51.1.81, contains a flaw in the kng_maintenance_page shortcode that does not perform capability, post‑status, or password checks before rendering a user‑supplied post. As a result, users with at least Contributor level privileges can view the content of private, draft, pending, and password‑protected posts that they are not authorized to access, exposing confidential post data to unauthorised readers.

Affected Systems

WordPress sites that have the King Addons for Elementor plugin installed at a version lower than 51.1.81. Every user role above Contributor—including editors and administrators—may exploit the flaw; site owners using older versions of the plugin are therefore at risk.

Risk and Exploitability

The CVSS score of 2.7 indicates a low overall severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The exploitation pathway involves deploying the vulnerable shortcode within a post or page that a Contributor can edit; the lack of validation allows the post’s private content to be rendered to the contributor’s browser. This attack requires only ordinary WordPress authoring permissions and can be carried out without network-level privileges, resulting in private content disclosure. Based on the description, the likely attack vector is through the web interface by creating or editing content that includes the shortcode.

Generated by OpenCVE AI on September 19, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade King Addons for Elementor to version 51.1.81 or higher.
  • If an immediate upgrade is not possible, restrict Contributor and lower roles from using the kng_maintenance_page shortcode by editing the plugin’s shortcode registration to require higher capabilities.
  • Re‑apply proper access control settings to ensure that private, draft, and password‑protected posts remain invisible to users with only Contributor privileges, following the CWE‑200 guidance on confidential data exposure prevention.

Generated by OpenCVE AI on September 19, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Kingaddons
Kingaddons king Addons For Elementor
Wordpress-extensions
Wordpress-extensions king Addons For Elementor
Vendors & Products Kingaddons
Kingaddons king Addons For Elementor
Wordpress-extensions
Wordpress-extensions king Addons For Elementor

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access.
Title King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng_maintenance_page Shortcode
References

Subscriptions

Kingaddons King Addons For Elementor
Wordpress-extensions King Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:12:39.500Z

Reserved: 2026-09-02T15:25:49.713Z

Link: CVE-2026-84903

cve-icon Vulnrichment

Updated: 2026-09-18T11:05:33.155Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:39.520

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-84903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor