Impact
The vulnerability in the King Addons for Elementor WordPress plugin allows authenticated users with author-level permissions to perform image‑optimization actions on media owned by other users without per‑object authorization checks. Because the plugin only checks a coarse capability that authors possess and does not verify ownership, an attacker can disclose the absolute file paths of other users’ media, overwrite the contents of those files, and cause site‑wide remapping of media references. This leads to information leakage and potential loss of data integrity for administrators and higher‑privileged users.
Affected Systems
Affected products are the King Addons for Elementor WordPress plugin, versions 51.1.56 through 51.1.80 (any release prior to 51.1.81). Users running these versions on any WordPress installation are vulnerable.
Risk and Exploitability
The CVSS score of 3.8 indicates low overall severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be authenticated with author-level or higher access, so the attack vector is local and requires legitimate credentials or a compromised author account.
OpenCVE Enrichment