CVE-2026-84904: King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer

Published Sep 18, 2026
·
Updated

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.

Affected Software

1 affected component
King Addons King Addons for Elementor<51.1.81

Event History

Sep 18, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

Any authenticated user with author-level access or above can exploit the affected image-optimization actions. The issue can be used against media objects belonging to other users, including administrators.

2

Are sites using the default affected plugin version range exposed?

Yes. The vulnerable behavior is present in King Addons for Elementor versions 51.1.56 through 51.1.80 because the affected actions rely on a coarse capability rather than per-object authorization or ownership validation.

3

What can an attacker do with this access?

An attacker can disclose absolute file paths, overwrite the bytes of media owned by other users, and change media references site-wide. Exploitation requires an authenticated account with at least author-level privileges.

4

How can I determine whether my site is affected?

Check the installed King Addons for Elementor version. Versions before 51.1.81 are affected; review whether author or higher-role accounts exist that should not be able to modify or access media belonging to other users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203