PT-2026-95236 · WordPress · Qi Addons For Elementor

·

CVE-2026-84904

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions King Addons for Elementor versions prior to 51.1.81
Description The plugin fails to perform per-object authorization checks for image-optimization actions. It relies on a coarse capability shared by lower-privileged users and does not verify ownership of the targeted object. This allows authenticated users with author-level access or higher to disclose absolute file paths, overwrite bytes, and re-reference media belonging to other users, including administrators.
Recommendations Update to version 51.1.81 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84904

Affected Products

Qi Addons For Elementor