Cross Site Scripting Vulnerability in King Addons for Elementor by Patch Stack
CVE-2026-96835
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-96835?
A vulnerability has been identified in the King Addons for Elementor plugin, allowing attackers to exploit Cross Site Scripting (XSS) in versions up to 51.1.85. This weakness can enable unauthorized scripts to be injected into web pages, potentially leading to data theft or user session hijacking. Users of this plugin are advised to update to the latest version to mitigate the associated risks.
Affected Version(s)
King Addons for Elementor <= 51.1.85