King Addons for Elementor <= 51.1.75 - Reflected XSS via Posts Grid Widget
medium
The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 51.1.75 due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 6.1
- Affected:
- up to 51.1.75
- Fixed in:
- 51.1.76
- Disclosed:
- Jul 20, 2026
CVE-2026-14841 on NVD →
King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
medium
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quot...
- CVSS:
- 6.4
- Affected:
- up to 51.1.62
- Fixed in:
- 51.1.63
- Disclosed:
- Jun 15, 2026
CVE-2026-15284 on NVD →
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 51.1.62
- Fixed in:
- 51.1.63
- Disclosed:
- Jun 2, 2026
CVE-2026-48870 on NVD →
King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets
medium
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr...
- CVSS:
- 6.4
- Affected:
- up to 51.1.53
- Fixed in:
- 51.1.54
- Disclosed:
- Mar 31, 2026
CVE-2025-13535 on NVD →
King Addons for Elementor - Unauthenticated API Keys Disclosure vulnerability
medium
Unauthenticated API Keys Disclosure vulnerability
- CVSS:
- 5.3
- Affected:
- up to 51.1.49
- Fixed in:
- 51.1.51
- Disclosed:
- Mar 24, 2026
King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure
medium
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via render_full_form functi...
- CVSS:
- 5.3
- Affected:
- up to 51.1.49
- Fixed in:
- 51.1.51
- Disclosed:
- Mar 22, 2026
CVE-2025-13997 on NVD →
King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This make...
- CVSS:
- 6.4
- Affected:
- up to 51.1.39
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-7960 on NVD →
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
critical
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated...
- CVSS:
- 9.8
- Affected:
- 24.12.92 – 51.1.14
- Fixed in:
- 51.1.35
- Disclosed:
- Oct 30, 2025
CVE-2025-8489 on NVD →
King Addons for Elementor <= 51.1.36 - Unauthenticated Arbitrary File Upload
critical
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 51.1.36. This makes it possible for unauthenticated attackers to upload a...
- CVSS:
- 9.8
- Affected:
- up to 51.1.36
- Fixed in:
- 51.1.37
- Disclosed:
- Oct 21, 2025
CVE-2025-6327 on NVD →
King Addons for Elementor <= 51.1.36 - Unauthenticated Privilege Escalation
critical
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 51.1.36. This makes it possible for unauthenticated attackers to register as site administrators.
- CVSS:
- 9.8
- Affected:
- up to 51.1.36
- Fixed in:
- 51.1.37
- Disclosed:
- Oct 21, 2025
CVE-2025-6325 on NVD →
King Addons for Elementor <= 51.1.62 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 51.1.62
- Fixed in:
- 51.1.63
- Disclosed:
- Aug 18, 2025
CVE-2025-62887 on NVD →
King Addons for Elementor <= 51.1.62 - Missing Authorization
medium
The King Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 51.1.62. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 51.1.62
- Fixed in:
- 51.1.63
- Disclosed:
- Aug 18, 2025
CVE-2025-62889 on NVD →
King Addons for Elementor <= 24.12.58 - Missing Authorization
medium
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 24.12.58. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 4.3
- Affected:
- up to 24.12.58
- Fixed in:
- 24.12.59
- Disclosed:
- Mar 27, 2025
CVE-2025-30926 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database