Subscriber Cross Site Scripting Vulnerability in King Addons for Elementor by PatchStack
CVE-2026-48870

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-48870?

A vulnerability has been identified in King Addons for Elementor, specifically versions equal to or lower than 51.1.62, where a Subscriber role user can exploit the application through Cross Site Scripting (XSS). This could lead to the injection of malicious scripts, compromising the integrity of the site and potentially allowing unauthorized access to sensitive information. It is crucial for users to update their plugins to mitigate the risks associated with this security flaw.

Affected Version(s)

King Addons for Elementor <= 51.1.62

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thevietronin | Patchstack Bug Bounty Program
.