PT-2026-95236 · WordPress · Qi Addons For Elementor
CVSS v3.1
3.8
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
King Addons for Elementor versions prior to 51.1.81
Description
The plugin fails to perform per-object authorization checks for image-optimization actions. It relies on a coarse capability shared by lower-privileged users and does not verify ownership of the targeted object. This allows authenticated users with author-level access or higher to disclose absolute file paths, overwrite bytes, and re-reference media belonging to other users, including administrators.
Recommendations
Update to version 51.1.81 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Addons For Elementor