Sceawere
Vulnerability Detail
CVE-2026-96835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
King Addons Contributor XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- KingAddons.com
- Product
- King Addons for Elementor
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:33.410Z",
"pubdate": "2026-09-30T13:17:33.410Z",
"executiveSummary": "The King Addons for Elementor plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 51.1.85.\nThis vulnerability originates from improper input validation and output sanitization within the plugin's configuration settings or widget parameters.\nA malicious actor with Contributor-level privileges or higher can inject arbitrary JavaScript payloads into the plugin's data structures, which are subsequently executed in the context of an administrator's browser session upon viewing the compromised page or dashboard.\nThe impact includes potential account takeover, unauthorized actions performed on behalf of an administrator, session hijacking, and the potential exfiltration of sensitive site data.\nSuccessful exploitation requires the attacker to hold an authenticated user account with at least Contributor permissions, making this an authenticated privilege escalation and exploitation vector.\nThis vulnerability highlights a lack of sufficient sanitization protocols for user-supplied data that is later rendered in the WordPress admin interface.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the insecure handling of user-supplied input provided via the plugin's interface. Within the affected versions (<= 51.1.85), King Addons for Elementor fails to sanitize or escape specific inputs before storing them in the WordPress database.\nWhen a user with Contributor-level access interacts with the plugin's configuration settings or widget options, they are capable of injecting malicious scripts, such as standard JavaScript <script> tags or event handlers like 'onerror' or 'onload' into input fields that do not implement strict output encoding.\nThe attack flow proceeds as follows: First, the authenticated contributor navigates to the plugin settings or widget customization panel. Second, the attacker inserts a crafted malicious payload into a vulnerable field—typically one that stores site-wide configurations or specific Elementor widget parameters. Third, the plugin saves this payload directly to the WordPress database without performing necessary cross-site scripting prevention checks.\nWhen an administrator or a user with higher privileges subsequently views the affected component within the WordPress dashboard or an Elementor-rendered page, the server returns the stored, unsanitized payload to the user's browser. The victim's browser, lacking instruction to treat the input as plain text, executes the injected script within the context of the WordPress admin panel.\nThis execution environment is highly privileged, allowing the injected script to leverage the current administrator's session. Potential post-exploitation activities include the creation of new administrative accounts, modification of site configuration files via the theme editor, or the redirection of site traffic to malicious domains. The vulnerability is persistent, meaning the malicious payload will execute every time an authorized user views the compromised input field until the data is manually removed from the database or the plugin is updated and patched. Because the plugin does not implement proper nonces or capability checks for these specific input streams, the risk of escalation is significant for sites with multiple contributors."
}