Impact
A cross‑site scripting flaw exists in the King Addons for Elementor plugin up to version 51.1.85. The vulnerability allows an attacker to insert malicious JavaScript into web page content that is rendered by the plugin, enabling theft of user credentials, cookie data, or other sensitive information captured from the victim’s browser. The impact is limited to confidentiality, integrity, and availability of data accessed by infected users but does not grant remote code execution on the host itself.
Affected Systems
Any WordPress site running King Addons for Elementor version 51.1.85 or earlier is affected. The plugin is widely used as a page‑builder extension, so multiple public websites may be at risk if they have not updated to a newer version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the injection of user‑controlled data that the plugin echoes without proper sanitization; the attacker therefore needs the ability to create or modify content that the plugin processes. While exploitation requires user interaction to render the page, the potential for damage is significant if attackers target high‑traffic sites.
OpenCVE Enrichment