Skip to main content
Vulnerability Database/CVE-2026-84904

CVE-2026-84904: King Addons Privilege Escalation Flaw

CVE-2026-84904 is a privilege escalation vulnerability in King Addons for Elementor WordPress plugin that lets author-level users manipulate media files. This post explains its impact, affected versions, and mitigation steps.

Updated:

CVE-2026-84904 Overview

CVE-2026-84904 is a missing authorization vulnerability [CWE-862] in the King Addons for Elementor WordPress plugin before version 51.1.81. The plugin exposes a group of image-optimization actions that check only a coarse capability held by lower-privileged users. The actions never verify ownership of the targeted media object. Authenticated users with author-level access or above can disclose absolute file paths, overwrite media bytes, and site-wide re-reference media belonging to other users, including administrators.

Critical Impact

Author-level accounts can tamper with administrator-owned media, altering site content and potentially replacing trusted image assets with attacker-controlled bytes.

Affected Products

  • King Addons for Elementor WordPress plugin versions prior to 51.1.81
  • WordPress sites permitting author-level (or higher) registration
  • Multi-author WordPress deployments using King Addons image optimization

Discovery Timeline

  • 2026-09-18 - CVE-2026-84904 published to the National Vulnerability Database (NVD)
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-84904

Vulnerability Analysis

The King Addons for Elementor plugin registers a set of image-optimization AJAX actions intended to let authors manage their own media. The handlers rely on a broad capability check that many roles satisfy. They never confirm that the requesting user owns the target attachment. This gap allows any authenticated author, editor, or contributor to invoke the actions against media belonging to any other user, including administrators.

The vulnerability affects three distinct operations. First, an attacker can request absolute filesystem paths for arbitrary attachments, disclosing server layout details. Second, an attacker can overwrite the raw bytes of another user's uploaded images. Third, an attacker can rewrite site-wide references so that content pointing to the original media resolves to attacker-chosen media.

Root Cause

The root cause is a missing per-object authorization check [CWE-862]. The affected handlers gate access with a single capability that lower-privileged users legitimately hold. They omit the ownership comparison between the current user ID and the attachment's post_author field. WordPress capability checks alone do not enforce object-level ownership, so the coarse gate is insufficient for actions that modify user-owned resources.

Attack Vector

Exploitation requires an authenticated session with author-level privileges or higher. The attacker sends crafted AJAX requests to the vulnerable image-optimization endpoints, supplying an attachment ID owned by another user. Because the handlers accept the request without validating ownership, the operation proceeds against the target attachment. Refer to the WPScan Vulnerability Report for endpoint-level details.

Detection Methods for CVE-2026-84904

Indicators of Compromise

  • Unexpected modification timestamps on administrator-owned attachments in wp-content/uploads/
  • AJAX requests to King Addons image-optimization actions originating from author or editor accounts referencing attachment IDs they do not own
  • Site pages where image URLs resolve to media authored by a different user than the surrounding content
  • Web server logs showing repeated POST requests to admin-ajax.php with King Addons action parameters from low-privileged sessions

Detection Strategies

  • Correlate WordPress post_author values with the acting user ID in AJAX handler audit logs to identify cross-user attachment operations
  • Alert on file hash changes for media files whose owning user did not initiate an upload or edit event
  • Monitor for enumeration patterns where a single low-privileged account references large ranges of attachment IDs

Monitoring Recommendations

  • Enable WordPress audit logging to capture attachment modification events with the initiating user ID
  • Baseline attachment file hashes and monitor wp-content/uploads/ for unauthorized byte-level changes
  • Track privilege distribution across accounts and review any author, editor, or contributor accounts created outside standard onboarding

How to Mitigate CVE-2026-84904

Immediate Actions Required

  • Upgrade the King Addons for Elementor plugin to version 51.1.81 or later on all WordPress sites
  • Audit existing author, editor, and contributor accounts for legitimacy and disable any that are unnecessary
  • Review recent attachment modifications and restore any media that shows unauthorized changes from backups
  • Rotate credentials for administrator accounts whose media may have been re-referenced or overwritten

Patch Information

The plugin vendor addressed the missing authorization checks in King Addons for Elementor version 51.1.81. The fixed release adds per-object ownership verification to the image-optimization action handlers. Consult the WPScan Vulnerability Report for the authoritative advisory reference.

Workarounds

  • Restrict new user registration and limit author-level or higher access to trusted personnel until the patch is applied
  • Temporarily deactivate the King Addons for Elementor plugin on sites that cannot upgrade immediately
  • Apply web application firewall rules to block AJAX requests to King Addons image-optimization actions from non-administrator sessions
bash
# Configuration example: verify installed plugin version and update via WP-CLI
wp plugin get king-addons-for-elementor --field=version
wp plugin update king-addons-for-elementor --version=51.1.81
wp plugin list --status=active | grep king-addons

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.