CVE-2026-84896
N/A
N/A
Summary
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | King Addons for Elementor | 0 < 51.1.77 | affected |
Weaknesses
- CWE-79 Cross-Site Scripting (XSS)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.