PT-2026-57061 · WordPress · Qi Addons For Elementor

·

CVE-2026-15284

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions King Addons for Elementor versions prior to 51.1.63
Description Stored Cross-Site Scripting (XSS) occurs when an application includes untrusted data in a web page without proper validation or escaping, allowing a malicious script to be permanently stored on the server and executed in the browser of other users. The issue exists due to insufficient input sanitization in the add to submissions() function, which uses sanitize text field() on the form page id parameter, failing to remove double-quote characters before storing the value in post meta. Additionally, the king addons submissions custom column content() function fails to escape the stored value using esc url() when concatenating it into an HTML href attribute via admin url(). Authenticated attackers with subscriber-level access or higher can exploit this to inject arbitrary web scripts that execute when a user accesses the affected page.
Recommendations Update King Addons for Elementor to a version newer than 51.1.62.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15284

Affected Products

Qi Addons For Elementor