Cross-Site Scripting Vulnerability in King Addons for Elementor by WP Engine
CVE-2026-14841
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14841?
The King Addons for Elementor plugin for WordPress, prior to version 51.1.76, contains a vulnerability that allows attackers to inject arbitrary JavaScript into the browser of a user through an unauthenticated AJAX response. By exploiting this weakness, a malicious actor can create a specially crafted page that, when visited by unsuspecting users, triggers the execution of harmful scripts. This can lead to a variety of harmful effects, including the theft of sensitive information or session hijacking.
Affected Version(s)
King Addons for Elementor 0 < 51.1.76
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.