Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84902 | 2 Kingaddons, Wordpress-extensions | 2 King Addons For Elementor, King Addons For Elementor | 2026-09-29 | 6.8 Medium |
| The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators, and to inject JavaScript through a widget setting that is output without escaping, resulting in Stored Cross-Site Scripting that executes in the session of any user who views the affected page. | ||||
| CVE-2026-84903 | 2 Kingaddons, Wordpress-extensions | 2 King Addons For Elementor, King Addons For Elementor | 2026-09-29 | 2.7 Low |
| The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level access and above to read the content of private, draft, pending, and password-protected posts they are not authorized to access. | ||||
| CVE-2026-84904 | 2 Kingaddons, Wordpress-extensions | 2 King Addons For Elementor, King Addons For Elementor | 2026-09-29 | 3.8 Low |
| The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and never confirming ownership of the targeted object, allowing authenticated users with author-level access and above to disclose absolute file paths for, overwrite the bytes of, and site-wide re-reference media belonging to other users, including administrators. | ||||
Page 1 of 1.