SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84896

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The King Addons for Elementor WordPress plugin prior to version 51.1.77 is vulnerable due to improper escaping of a widget display-style setting, enabling users with Contributor-level access and higher to inject malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, affecting any visitor to the page, including logged-in administrators. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-84896
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress Java

Original NVD Description

The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.