Description
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Published: 2026-09-30
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Cross Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Contributor Cross Site Scripting (XSS) vulnerability allows an attacker to inject malicious script through the King Addons for Elementor plugin when accessing or inputting data. This flaw can be leveraged to execute arbitrary JavaScript in the context of a visitor's browser, potentially enabling session hijacking, credential theft, defacement, or the execution of additional malware. The impact is primarily on confidentiality and integrity of user data, and can be used to perform phishing or other social engineering attacks on site visitors.

Affected Systems

King Addons for Elementor plugin for WordPress users running version 51.1.86 or earlier are affected. This includes all installations that have not applied the latest patch upgrade.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating a medium risk. The EPSS score is not available and it is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. However, given the nature of XSS, an attacker who can supply content to the plugin could likely exploit it, especially if the plugin is exposed to user‑generated input.

Generated by OpenCVE AI on September 30, 2026 at 15:52 UTC.

Remediation

Vendor Solution

Update the WordPress King Addons for Elementor plugin to the latest available version (at least 51.1.87).


OpenCVE Recommended Actions

  • Update the King Addons for Elementor plugin to version 51.1.87 or later, which removes the XSS flaw.
  • If an immediate update is not possible, disable or uninstall the plugin to eliminate the attack surface.
  • Consider applying additional input validation or sanitization to content managed by the plugin until the patch is applied.

Generated by OpenCVE AI on September 30, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Title WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:16.320Z

Reserved: 2026-09-24T10:23:27.497Z

Link: CVE-2026-97298

cve-icon Vulnrichment

Updated: 2026-09-30T13:26:20.431Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:39.623

Modified: 2026-09-30T14:18:18.587

Link: CVE-2026-97298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')