CVE-2026-84904: King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Optimizer
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated user with author-level access or above can exploit the affected image-optimization actions. The issue can be used against media objects belonging to other users, including administrators.
Are sites using the default affected plugin version range exposed?
Yes. The vulnerable behavior is present in King Addons for Elementor versions 51.1.56 through 51.1.80 because the affected actions rely on a coarse capability rather than per-object authorization or ownership validation.
What can an attacker do with this access?
An attacker can disclose absolute file paths, overwrite the bytes of media owned by other users, and change media references site-wide. Exploitation requires an authenticated account with at least author-level privileges.
How can I determine whether my site is affected?
Check the installed King Addons for Elementor version. Versions before 51.1.81 are affected; review whether author or higher-role accounts exist that should not be able to modify or access media belonging to other users.