Skip to main content
Vulnerability Database/CVE-2026-84903

CVE-2026-84903: King Addons Elementor Info Disclosure Flaw

CVE-2026-84903 is an information disclosure vulnerability in King Addons for Elementor WordPress plugin that allows Contributors to read private and draft posts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-84903 Overview

CVE-2026-84903 affects the King Addons for Elementor WordPress plugin in versions prior to 51.1.81. The plugin renders the content of a user-supplied post without performing capability, post-status, or password checks. Authenticated users with Contributor-level access or higher can retrieve the content of private, draft, pending, and password-protected posts they should not be able to read. The flaw is categorized as an information exposure issue [CWE-200].

Critical Impact

Contributor-level accounts can access unpublished and password-protected post content across the WordPress site, bypassing WordPress access controls.

Affected Products

  • King Addons for Elementor WordPress plugin, all versions before 51.1.81

Discovery Timeline

  • 2026-09-18 - CVE-2026-84903 published to the National Vulnerability Database
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-84903

Vulnerability Analysis

The King Addons for Elementor plugin exposes a rendering path that accepts an arbitrary post identifier from the request and returns the rendered post content. WordPress normally gates access to posts based on post status (private, draft, pending, future) and, for password-protected posts, requires the correct password before revealing content. The vulnerable code path skips these checks entirely.

An authenticated user with the edit_posts capability, granted to the Contributor role and above, can supply the ID of any post on the site. The plugin returns the rendered content regardless of the requesting user's authorization to view that post. This allows disclosure of unpublished editorial content, private posts intended for restricted audiences, and password-protected content without knowledge of the password.

Root Cause

The root cause is missing authorization enforcement in the post-rendering handler. The code does not call current_user_can() against the target post, does not inspect the target post's status via get_post_status(), and does not validate the password cookie for password-protected posts. The result is a broken access control condition ([CWE-200]) where post visibility rules defined by WordPress core are not honored by the plugin.

Attack Vector

Exploitation requires an authenticated session with Contributor privileges or higher. The attacker issues a request to the vulnerable plugin endpoint and supplies the target post identifier. The server returns the rendered content of the requested post. No user interaction is required beyond the attacker's own request, and no additional privileges beyond Contributor are needed. See the WPScan Vulnerability Report for advisory details.

Detection Methods for CVE-2026-84903

Indicators of Compromise

  • Requests from Contributor-level accounts to King Addons for Elementor rendering endpoints that reference post IDs outside of that user's authored posts.
  • Access log entries showing repeated enumeration of sequential post_id or p parameter values by low-privilege authenticated users.
  • Unexpected views on private, draft, or password-protected posts recorded in WordPress activity or analytics logs.

Detection Strategies

  • Correlate WordPress user role information with HTTP request logs to identify Contributor accounts accessing content owned by other authors.
  • Alert on authenticated requests to King Addons rendering handlers where the referenced post's status is private, draft, pending, or password-protected.
  • Deploy a Web Application Firewall rule that flags requests containing King Addons render parameters combined with post_id values not owned by the requester.

Monitoring Recommendations

  • Enable WordPress audit logging to capture post access events, including the requesting user, post ID, and post status.
  • Forward web server access logs and WordPress audit logs to a centralized analytics platform for correlation and long-term retention.
  • Review Contributor and Author account activity for post-ID enumeration patterns on a recurring basis.

How to Mitigate CVE-2026-84903

Immediate Actions Required

  • Upgrade King Addons for Elementor to version 51.1.81 or later on all WordPress sites where the plugin is installed.
  • Audit existing Contributor, Author, and Editor accounts and remove or downgrade accounts that are no longer needed.
  • Rotate passwords on any password-protected posts that contain sensitive content in case the content was previously disclosed.

Patch Information

The vendor addressed the issue in King Addons for Elementor version 51.1.81. The fix adds capability, post-status, and password validation before rendering user-supplied post content. Refer to the WPScan Vulnerability Report for the current advisory record.

Workarounds

  • Temporarily disable the King Addons for Elementor plugin until the update to 51.1.81 or later is applied.
  • Restrict site registration and remove untrusted Contributor accounts to limit the pool of users able to exploit the flaw.
  • Deploy a Web Application Firewall rule that blocks requests to the King Addons render handler when the target post status is not publish and the requester is not the post author.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.