WordPress Plugin Vulnerabilities
King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
Description
The plugin does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
V1T
Submitter
V1T
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-20 (about 13 days ago)
Added
2026-07-20 (about 12 days ago)
Last Updated
2026-07-20 (about 12 days ago)