Executive brief
King Addons for Elementor is a popular WordPress plugin that extends the Elementor page builder with additional design components. An unauthenticated attacker can exploit an insecure direct object reference vulnerability to access and view other users' data by manipulating IDs in URLs, potentially exposing sensitive information without needing credentials.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability classified under OWASP Top 10 A1 (Broken Access Control). The vulnerability exists in King Addons for Elementor versions up to 51.1.81 and can be exploited by unauthenticated attackers with network access. By modifying object identifiers in URLs, an attacker can bypass authorization checks and directly access or view data belonging to other users. No authentication is required and no user interaction is needed. The vulnerability has been patched in version 51.1.82 and later.
Affected products
- King Addons King Addons for Elementor <=51.1.81
Timeline
- 2026-09-13: disclosed
- 2026-09-17: advisory
- 2026-09-17: patched: Fixed in version 51.1.82