CyberRota Analysis
AI-GeneratedThe King Addons for Elementor WordPress plugin prior to version 51.1.77 is vulnerable due to improper escaping of a widget display-style setting, enabling users with Contributor-level access and higher to inject malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, affecting any visitor to the page, including logged-in administrators. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.