Cross Site Scripting Vulnerability in King Addons for Elementor by King Plugins
CVE-2026-97298
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-97298?
A Cross Site Scripting (XSS) vulnerability has been identified in the King Addons for Elementor plugin, affecting versions up to 51.1.86. This flaw may allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and allowing unauthorized actions. It is crucial for users of this plugin to apply necessary patches or update to secure versions to protect against potential exploitation.
Affected Version(s)
King Addons for Elementor <= 51.1.86