Junglewise Threat Intelligence

CVE-2026-66575: King Addons for Elementor insecure direct object reference

CVE-2026-66575 · Severity: medium · CVSS 5.3 · Published 2026-09-17

Technologies: King Addons for Elementor. Vendors: King Addons.

Executive brief

King Addons for Elementor is a popular WordPress plugin that extends the Elementor page builder with additional design components. An unauthenticated attacker can exploit an insecure direct object reference vulnerability to access and view other users' data by manipulating IDs in URLs, potentially exposing sensitive information without needing credentials.

Technical details

This is an Insecure Direct Object Reference (IDOR) vulnerability classified under OWASP Top 10 A1 (Broken Access Control). The vulnerability exists in King Addons for Elementor versions up to 51.1.81 and can be exploited by unauthenticated attackers with network access. By modifying object identifiers in URLs, an attacker can bypass authorization checks and directly access or view data belonging to other users. No authentication is required and no user interaction is needed. The vulnerability has been patched in version 51.1.82 and later.

Affected products

  • King Addons King Addons for Elementor <=51.1.81

Timeline

  • 2026-09-13: disclosed
  • 2026-09-17: advisory
  • 2026-09-17: patched: Fixed in version 51.1.82

References

Related threats