Skip to main content
Vulnerability Database/CVE-2026-84896

CVE-2026-84896: King Addons for Elementor XSS Vulnerability

CVE-2026-84896 is a stored cross-site scripting vulnerability in King Addons for Elementor WordPress plugin that allows contributors to inject malicious JavaScript. This post covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-84896 Overview

CVE-2026-84896 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the King Addons for Elementor WordPress plugin in versions prior to 51.1.77. The plugin fails to escape a widget display-style setting before outputting it inside an HTML attribute. Authenticated users with Contributor-level access or higher can inject JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators. Successful exploitation can lead to administrator session hijacking, arbitrary actions performed on behalf of privileged users, and full site compromise through further payload delivery.

Critical Impact

A Contributor-level account can store JavaScript that runs in an administrator's browser, enabling account takeover and further compromise of the WordPress site.

Affected Products

  • King Addons for Elementor WordPress plugin versions before 51.1.77
  • WordPress sites using Elementor with the vulnerable plugin installed
  • Any site permitting Contributor-level or higher account registration with the plugin enabled

Discovery Timeline

  • 2026-09-05 - CVE-2026-84896 published to NVD
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-84896

Vulnerability Analysis

The vulnerability resides in how the King Addons for Elementor plugin handles a widget display-style configuration value. When rendering the widget, the plugin inserts the user-controlled setting directly into an HTML attribute without applying output escaping. This allows an attacker to break out of the attribute context using quote characters and inject arbitrary JavaScript.

Because the payload is persisted in the widget configuration, it fires every time the page is rendered in a browser. Any visitor viewing the affected page, including authenticated administrators, becomes an execution target. The stored nature of the flaw makes it significantly more impactful than reflected XSS, as no social engineering is required to reach a victim.

Root Cause

The root cause is missing output encoding for a widget display-style attribute value. Under WordPress security practices, values placed inside HTML attributes must be escaped using functions such as esc_attr(). The affected plugin code omits this step, so raw user input reaches the attribute context and is parsed by the browser as executable content.

Attack Vector

Exploitation requires an authenticated account with Contributor-level access or above. The attacker configures a widget with a malicious display-style value containing a JavaScript payload. Once the widget is added to a page and rendered, the injected script executes in the context of the site's origin for every visitor. High-privilege victims such as administrators expose session cookies, nonces, and privileged API endpoints to the attacker. Additional technical detail is available in the WPScan Vulnerability Report.

Detection Methods for CVE-2026-84896

Indicators of Compromise

  • Widget display-style configuration values containing HTML control characters, <script> tags, or event-handler attributes such as onerror= and onload=.
  • Unexpected creation or modification of pages, posts, or widgets by Contributor-level accounts.
  • Outbound browser requests from administrator sessions to unfamiliar domains shortly after visiting content pages.

Detection Strategies

  • Review the plugin version in use and confirm whether it is older than 51.1.77.
  • Audit wp_postmeta and Elementor page data for stored widget settings containing suspicious characters or script fragments.
  • Correlate WordPress user activity logs to identify Contributor-level accounts editing widgets or page templates.

Monitoring Recommendations

  • Enable a Web Application Firewall (WAF) with rules for stored XSS patterns targeting WordPress content endpoints.
  • Monitor administrator session activity for anomalies such as new user creation, plugin installation, or role changes originating from unusual IP addresses.
  • Log and alert on changes to Elementor widget configurations, particularly by non-Editor accounts.

How to Mitigate CVE-2026-84896

Immediate Actions Required

  • Upgrade King Addons for Elementor to version 51.1.77 or later on all WordPress instances.
  • Audit existing Contributor, Author, and Editor accounts, removing any that are unnecessary or inactive.
  • Inspect all Elementor pages built with King Addons widgets for stored script payloads and remove them.

Patch Information

The vendor addressed the issue in King Addons for Elementor version 51.1.77 by properly escaping the widget display-style value before HTML attribute output. Refer to the WPScan Vulnerability Report for advisory details.

Workarounds

  • Restrict user registration and disable Contributor-level or higher access for untrusted users until the patch is applied.
  • Temporarily disable the King Addons for Elementor plugin if upgrading is not immediately feasible.
  • Deploy a WAF rule to block requests containing script tags or event handlers in Elementor widget setting parameters.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.