SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14841

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The King Addons for Elementor WordPress plugin is vulnerable due to improper escaping of user-supplied grid settings in unauthenticated AJAX responses, potentially allowing attackers to execute arbitrary JavaScript in the browsers of unsuspecting visitors. This could lead to session hijacking, data theft, or other malicious activities. WordPress site administrators using this plugin should prioritize updating to version 51.1.76 or later to mitigate this risk.

CVE
CVE-2026-14841
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%
WordPress Java

Original NVD Description

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.