plugin

King Addons Vulnerabilities

13 known security issues reported for the King Addons WordPress plugin. Most recent disclosed Jul 20, 2026.

3 critical 10 medium

Running King Addons on your site? Check whether your installed version is affected.

Scan your site free

King Addons for Elementor <= 51.1.75 - Reflected XSS via Posts Grid Widget

medium

The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 51.1.75 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
6.1
Affected:
up to 51.1.75
Fixed in:
51.1.76
Disclosed:
Jul 20, 2026

CVE-2026-14841 on NVD →

King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter

medium

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quot...

CVSS:
6.4
Affected:
up to 51.1.62
Fixed in:
51.1.63
Disclosed:
Jun 15, 2026

CVE-2026-15284 on NVD →

King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 51.1.62
Fixed in:
51.1.63
Disclosed:
Jun 2, 2026

CVE-2026-48870 on NVD →

King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets

medium

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The plugin uses esc_attr...

CVSS:
6.4
Affected:
up to 51.1.53
Fixed in:
51.1.54
Disclosed:
Mar 31, 2026

CVE-2025-13535 on NVD →

King Addons for Elementor - Unauthenticated API Keys Disclosure vulnerability

medium

Unauthenticated API Keys Disclosure vulnerability

CVSS:
5.3
Affected:
up to 51.1.49
Fixed in:
51.1.51
Disclosed:
Mar 24, 2026

King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure

medium

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via render_full_form functi...

CVSS:
5.3
Affected:
up to 51.1.49
Fixed in:
51.1.51
Disclosed:
Mar 22, 2026

CVE-2025-13997 on NVD →

King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escaping on user supplied attributes. This make...

CVSS:
6.4
Affected:
up to 51.1.39
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-7960 on NVD →

King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation

critical

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated...

CVSS:
9.8
Affected:
24.12.92 – 51.1.14
Fixed in:
51.1.35
Disclosed:
Oct 30, 2025

CVE-2025-8489 on NVD →

King Addons for Elementor <= 51.1.36 - Unauthenticated Arbitrary File Upload

critical

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 51.1.36. This makes it possible for unauthenticated attackers to upload a...

CVSS:
9.8
Affected:
up to 51.1.36
Fixed in:
51.1.37
Disclosed:
Oct 21, 2025

CVE-2025-6327 on NVD →

King Addons for Elementor <= 51.1.36 - Unauthenticated Privilege Escalation

critical

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 51.1.36. This makes it possible for unauthenticated attackers to register as site administrators.

CVSS:
9.8
Affected:
up to 51.1.36
Fixed in:
51.1.37
Disclosed:
Oct 21, 2025

CVE-2025-6325 on NVD →

King Addons for Elementor <= 51.1.62 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 51.1.62
Fixed in:
51.1.63
Disclosed:
Aug 18, 2025

CVE-2025-62887 on NVD →

King Addons for Elementor <= 51.1.62 - Missing Authorization

medium

The King Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 51.1.62. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 51.1.62
Fixed in:
51.1.63
Disclosed:
Aug 18, 2025

CVE-2025-62889 on NVD →

King Addons for Elementor <= 24.12.58 - Missing Authorization

medium

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 24.12.58. This makes it possible for authenticated attackers, with Subscriber-leve...

CVSS:
4.3
Affected:
up to 24.12.58
Fixed in:
24.12.59
Disclosed:
Mar 27, 2025

CVE-2025-30926 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database