Sceawere

Vulnerability Detail

CVE-2026-96835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

King Addons Contributor XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
KingAddons.com
Product
King Addons for Elementor
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:33.410Z",
  "pubdate": "2026-09-30T13:17:33.410Z",
  "executiveSummary": "The King Addons for Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 51.1.85.\nThis vulnerability originates from improper input validation and output sanitization within the plugin's configuration settings or widget parameters.\nA malicious actor with Contributor-level privileges or higher can inject arbitrary JavaScript payloads into the plugin's data structures, which are subsequently executed in the context of an administrator's browser session upon viewing the compromised page or dashboard.\nThe impact includes potential account takeover, unauthorized actions performed on behalf of an administrator, session hijacking, and the potential exfiltration of sensitive site data.\nSuccessful exploitation requires the attacker to hold an authenticated user account with at least Contributor permissions, making this an authenticated privilege escalation and exploitation vector.\nThis vulnerability highlights a lack of sufficient sanitization protocols for user-supplied data that is later rendered in the WordPress admin interface.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the insecure handling of user-supplied input provided via the plugin's interface. Within the affected versions (<= 51.1.85), King Addons for Elementor fails to sanitize or escape specific inputs before storing them in the WordPress database.\nWhen a user with Contributor-level access interacts with the plugin's configuration settings or widget options, they are capable of injecting malicious scripts, such as standard JavaScript <script> tags or event handlers like 'onerror' or 'onload' into input fields that do not implement strict output encoding.\nThe attack flow proceeds as follows: First, the authenticated contributor navigates to the plugin settings or widget customization panel. Second, the attacker inserts a crafted malicious payload into a vulnerable field—typically one that stores site-wide configurations or specific Elementor widget parameters. Third, the plugin saves this payload directly to the WordPress database without performing necessary cross-site scripting prevention checks.\nWhen an administrator or a user with higher privileges subsequently views the affected component within the WordPress dashboard or an Elementor-rendered page, the server returns the stored, unsanitized payload to the user's browser. The victim's browser, lacking instruction to treat the input as plain text, executes the injected script within the context of the WordPress admin panel.\nThis execution environment is highly privileged, allowing the injected script to leverage the current administrator's session. Potential post-exploitation activities include the creation of new administrative accounts, modification of site configuration files via the theme editor, or the redirection of site traffic to malicious domains. The vulnerability is persistent, meaning the malicious payload will execute every time an authorized user views the compromised input field until the data is manually removed from the database or the plugin is updated and patched. Because the plugin does not implement proper nonces or capability checks for these specific input streams, the risk of escalation is significant for sites with multiple contributors."
}
CVE-2026-96835: King Addons Contributor XSS Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere