Executive brief
The King Addons for Elementor WordPress plugin allows users with contributor-level permissions to import templates without proper authorization checks, enabling them to overwrite page content owned by administrators and inject malicious code. An attacker with contributor access can deface websites and execute JavaScript in the browsers of all visitors, including administrators, potentially leading to account compromise or malware distribution.
Technical details
The vulnerability is a combination of missing object-level authorization and stored cross-site scripting (XSS). When a contributor-level user imports template content, the plugin does not verify they have permission to modify the target post or page, allowing overwrite of any Elementor content. Additionally, a widget setting in the template is output to the page without HTML escaping, permitting injection of arbitrary JavaScript. An attacker with contributor or higher role can exploit this via the template import functionality; no additional privileges or social engineering required. The malicious script executes server-side in the session context of any user viewing the affected page, including administrators. The vulnerability is patched in version 51.1.81.
Affected products
- King Addons King Addons for Elementor before 51.1.81
Timeline
- 2026-09-16: disclosed
- 2026-09-18: patched: Fixed in version 51.1.81