Junglewise Threat Intelligence

CVE-2026-48870: King Addons King Addons for Elementor Cross Site Scripting

CVE-2026-48870 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

King Addons for Elementor is a WordPress plugin used to add custom design elements and widgets to websites. A security vulnerability in this plugin allows users with basic 'Subscriber' accounts to inject malicious scripts into the site. If an administrator or visitor views the affected content, these scripts could redirect users to malicious websites, display unauthorized advertisements, or compromise user sessions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in King Addons for Elementor (versions <= 51.1.62) due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Subscriber' level privileges to initiate, but successful exploitation depends on user interaction from a victim (typically an administrator). An attacker can inject malicious HTML or JavaScript payloads that are stored on the server and executed in the context of other users' sessions. This can lead to unauthorized actions, data theft via cookies, or site defacement. The issue is resolved in version 51.1.63.

Affected products

  • King Addons King Addons for Elementor <= 51.1.62

Timeline

  • 2026-04-08: other: Reported by thevietronin
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-02: patched: Version 51.1.63 released

References

Related threats