← Back to CVE List
CVE-2026-84902NVD
Description
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| Unknown King Addons for Elementor | 0 - < 51.1.81 | N/A |