CVE-2026-84896: King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget
Published Sep 5, 2026
·Updated
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
Affected Software
1 affected component
King Addons King Addons for Elementor<51.1.77
Event History
Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with Contributor-level access or higher can exploit it by storing malicious JavaScript in the Magazine Grid widget's display-style setting.
2
Who is exposed if the issue is exploited?
Any visitor who views the affected page can have the stored JavaScript execute in their browser. This includes logged-in administrators.
3
Which plugin versions are affected?
King Addons for Elementor versions before 51.1.77 are affected.