CVE-2026-84902 Overview
CVE-2026-84902 affects the King Addons for Elementor WordPress plugin in versions prior to 51.1.81. The plugin fails to enforce object-level authorization when importing template content into a page. Users with contributor-level access or higher can overwrite the Elementor content of arbitrary posts and pages, including those owned by administrators. The flaw also allows injection of JavaScript through a widget setting that is output without escaping, producing Stored Cross-Site Scripting [CWE-79]. The injected script executes in the browser session of any user who views the affected page.
Critical Impact
A contributor-level account can overwrite administrator-owned pages and plant Stored XSS payloads that execute in every visitor's session, including administrators.
Affected Products
- King Addons for Elementor WordPress plugin versions before 51.1.81
- WordPress sites running Elementor with the vulnerable plugin installed
- Any site permitting contributor-level or higher user registrations
Discovery Timeline
- 2026-09-18 - CVE-2026-84902 published to NVD
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-84902
Vulnerability Analysis
The vulnerability chains two distinct defects into a single exploitable path. First, the template import handler does not verify that the requesting user owns or has edit rights on the target post or page. Second, a widget setting processed during import is written to the page output without proper escaping. Together, these defects convert a routine contributor account into a vehicle for site-wide Stored XSS. An attacker uses the import endpoint to select an arbitrary post_id, including one belonging to an administrator, and replaces its Elementor content with attacker-controlled markup. When any authenticated user browses the compromised page, the injected JavaScript runs under their origin and session context.
Root Cause
The root cause is a missing object-level authorization check in the template import routine. The plugin confirms the caller is authenticated and holds a contributor-or-above role but never validates edit permission on the specific target post. This is a Broken Access Control condition compounded by missing output encoding on a widget setting field, which allows raw script content to reach the rendered DOM.
Attack Vector
Exploitation requires an authenticated session with contributor privileges and one user interaction to trigger the payload. An attacker submits a crafted template import request that targets a post_id belonging to a privileged user and embeds JavaScript within the vulnerable widget setting. When an administrator or other visitor loads the page, the script executes, enabling session theft, forced administrative actions, plugin installation, or account takeover. Because the payload is stored, it persists until the page content is restored or the plugin is patched. Technical details are documented in the WPScan Vulnerability Details.
Detection Methods for CVE-2026-84902
Indicators of Compromise
- Unexpected modifications to Elementor page or post content, particularly on pages owned by administrators or editors
- Post revisions where the modifying user holds only contributor-level rights
- <script> tags, event handlers, or encoded JavaScript stored in Elementor widget settings within wp_postmeta under _elementor_data
- Outbound requests from visitor browsers to unfamiliar domains after loading affected pages
Detection Strategies
- Audit wp_posts and wp_postmeta for Elementor content changes performed by low-privilege accounts against high-privilege authors
- Inspect web server logs for POST requests to King Addons template import endpoints originating from contributor accounts
- Scan rendered page HTML for injected script tags or JavaScript URI handlers within Elementor widget output
Monitoring Recommendations
- Enable WordPress audit logging to record post updates, user role changes, and plugin activity with the originating user ID
- Alert on newly created administrator accounts or role escalations that follow contributor logins
- Monitor the King Addons plugin version across all sites and flag any instance below 51.1.81
How to Mitigate CVE-2026-84902
Immediate Actions Required
- Update the King Addons for Elementor plugin to version 51.1.81 or later on every WordPress site
- Review all contributor, author, and editor accounts and disable any that are unused or unrecognized
- Inspect Elementor content on administrator-owned pages for unauthorized modifications and restore from clean backups where necessary
- Force password resets and invalidate active sessions for privileged accounts that viewed potentially compromised pages
Patch Information
The vendor fixed the issue in King Addons for Elementor version 51.1.81. The patch adds an object-level authorization check to the template import handler and applies output escaping to the affected widget setting. Refer to the WPScan Vulnerability Details for reference material on the fix.
Workarounds
- Deactivate the King Addons for Elementor plugin until the patched version is installed
- Restrict new user registrations and remove contributor privileges from accounts that do not require them
- Deploy a web application firewall rule to block requests to the plugin's template import endpoint from non-administrator sessions
# Verify installed plugin version via WP-CLI
wp plugin get king-addons-for-elementor --field=version
# Update to the patched release
wp plugin update king-addons-for-elementor --version=51.1.81
# Temporary mitigation: deactivate the plugin site-wide
wp plugin deactivate king-addons-for-elementor
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
