PT-2026-57061 · WordPress · Qi Addons For Elementor
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
King Addons for Elementor versions prior to 51.1.63
Description
Stored Cross-Site Scripting (XSS) occurs when an application includes untrusted data in a web page without proper validation or escaping, allowing a malicious script to be permanently stored on the server and executed in the browser of other users. The issue exists due to insufficient input sanitization in the
add to submissions() function, which uses sanitize text field() on the form page id parameter, failing to remove double-quote characters before storing the value in post meta. Additionally, the king addons submissions custom column content() function fails to escape the stored value using esc url() when concatenating it into an HTML href attribute via admin url(). Authenticated attackers with subscriber-level access or higher can exploit this to inject arbitrary web scripts that execute when a user accesses the affected page.Recommendations
Update King Addons for Elementor to a version newer than 51.1.62.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Addons For Elementor