Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
Published: 2026-09-18
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: File path disclosure and modification via authorization bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability in the King Addons for Elementor WordPress plugin allows authenticated users with author-level permissions to perform image‑optimization actions on media owned by other users without per‑object authorization checks. Because the plugin only checks a coarse capability that authors possess and does not verify ownership, an attacker can disclose the absolute file paths of other users’ media, overwrite the contents of those files, and cause site‑wide remapping of media references. This leads to information leakage and potential loss of data integrity for administrators and higher‑privileged users.

Affected Systems

Affected products are the King Addons for Elementor WordPress plugin, versions 51.1.56 through 51.1.80 (any release prior to 51.1.81). Users running these versions on any WordPress installation are vulnerable.

Risk and Exploitability

The CVSS score of 3.8 indicates low overall severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be authenticated with author-level or higher access, so the attack vector is local and requires legitimate credentials or a compromised author account.

Generated by OpenCVE AI on September 19, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the King Addons for Elementor plugin to version 51.1.81 or newer, which contains the authorization fix for image‑optimizer actions.
  • If an upgrade is not immediately possible, restrict author‑level users from using the image‑optimizer feature or reduce their capability level in WordPress.
  • Consider disabling the image‑optimizer functionality via plugin settings or a custom code snippet until an official patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Kingaddons
Kingaddons king Addons For Elementor
Wordpress-extensions
Wordpress-extensions king Addons For Elementor
Vendors & Products Kingaddons
Kingaddons king Addons For Elementor
Wordpress-extensions
Wordpress-extensions king Addons For Elementor

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
Title King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer
References

Subscriptions

Kingaddons King Addons For Elementor
Wordpress-extensions King Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:12:25.031Z

Reserved: 2026-09-02T15:25:53.441Z

Link: CVE-2026-84904

cve-icon Vulnrichment

Updated: 2026-09-18T11:04:46.885Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:39.637

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-84904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:07Z

Weaknesses