« Volver al listado

Kingaddons

Kingaddons King Addons: vulnerabilidades y CVE

Kingaddons King Addons tiene 14 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses13
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97298Media (6.5)0.22%—30 sept 2026
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
CVE-2026-96835Media (6.5)0.22%—30 sept 2026
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
CVE-2026-84904Baja (3.8)0.26%—18 sept 2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged…
CVE-2026-84903Baja (2.7)0.32%—18 sept 2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password check before rendering the content of a user-supplied post, allowing users with Contributor-level…
CVE-2026-84902Media (6.8)0.43%—18 sept 2026
The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to…
CVE-2026-84896Media (6.8)0.43%—5 sept 2026
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store…
CVE-2026-14841Media (6.1)0.25%—2 ago 2026
The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute…
CVE-2026-15284Media (6.4)0.42%—10 jul 2026
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization…
CVE-2025-13535Media (6.4)0.24%—1 abr 2026
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient…
CVE-2025-13997Media (5.3)0.22%—23 mar 2026
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and…
CVE-2025-7960Media (6.4)0.18%—13 dic 2025
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including,…
CVE-2025-6325Crítica (9.8)0.40%—6 nov 2025
Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.
CVE-2025-8489Crítica (9.8)9.3%—31 oct 2025
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not…
CVE-2025-30926Media (4.3)0.31%—1 abr 2025
Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons.This issue affects King Addons for Elementor: from n/a through <= 24.12.58.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Kingaddons