CVE-2026-84902: King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated user with contributor-level access or higher can exploit it. The issue allows them to target arbitrary posts and pages, including content owned by administrators.
What must an attacker do for the XSS payload to execute?
The attacker must import crafted template content into a page and inject JavaScript through the affected widget setting. The payload executes when a user views the affected page.
How can I determine whether a site may be affected?
Sites using King Addons for Elementor versions earlier than 51.1.81 may be affected, particularly if contributor or higher roles are assigned to untrusted users. Review Elementor content on posts and pages for unauthorized template imports or suspicious widget settings.