CVE-2026-66575: WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress King Addons for Elementor pluginto a version that resolves this vulnerability.Fixed in 51.1.82
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
What is the potential impact?
The supplied CVSS vector indicates an integrity impact only (I:L), with no stated confidentiality or availability impact. The vulnerability can be exploited remotely over the network with low attack complexity and requires no user interaction.
Which installations are affected?
King Addons for Elementor versions 51.1.81 and earlier are identified as affected. The provided information does not state whether a particular configuration or feature must be enabled.