Extension WordPress
Vulnérabilités King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
Cette page rassemble les failles publiées pour King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
11 fiches
King Addons for Elementor <= 51.1.62 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies…
*-51.1.62
51.1.63
15/06/2026
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input…
*-51.1.62
51.1.63
02/06/2026
King Addons for Elementor <= 51.1.38 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple…
*-51.1.53
51.1.54
31/03/2026
King Addons for Elementor <= 51.1.49 – Unauthenticated API Keys Disclosure
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the…
*-51.1.49
51.1.51
22/03/2026
King Addons for Elementor <= 51.1.39 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization…
*-51.1.39
Non indiqué
12/12/2025
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 – 51.1.14 – Unauthenticated Privilege Escalation
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the…
24.12.92-51.1.14
51.1.35
30/10/2025
King Addons for Elementor <= 51.1.36 – Unauthenticated Arbitrary File Upload
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and…
*-51.1.36
51.1.37
21/10/2025
King Addons for Elementor <= 51.1.36 – Unauthenticated Privilege Escalation
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 51.1.36. This makes it possible for…
*-51.1.36
51.1.37
21/10/2025
King Addons for Elementor <= 51.1.62 – Missing Authorization
The King Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 51.1.62. This makes it possible for authenticated attackers, with contributor-level…
*-51.1.62
51.1.63
18/08/2025
King Addons for Elementor <= 51.1.62 – Authenticated (Contributor+) Stored Cross-Site Scripting
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-51.1.62
51.1.63
18/08/2025
King Addons for Elementor <= 24.12.58 – Missing Authorization
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-24.12.58
24.12.59
27/03/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.