Extension WordPress

Vulnérabilités King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

Cette page rassemble les failles publiées pour King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
3Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

11 fiches

CVE-2026-15284 Moyenne · 6,4
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.62 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies…

Versions affectées

*-51.1.62

Correctif

51.1.63

Publication

15/06/2026

CVE-2026-48870 Moyenne · 6,4
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input…

Versions affectées

*-51.1.62

Correctif

51.1.63

Publication

02/06/2026

CVE-2025-13535 Moyenne · 6,4
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.38 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Widgets

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple…

Versions affectées

*-51.1.53

Correctif

51.1.54

Publication

31/03/2026

CVE-2025-13997 Moyenne · 5,3
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.49 – Unauthenticated API Keys Disclosure

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the…

Versions affectées

*-51.1.49

Correctif

51.1.51

Publication

22/03/2026

CVE-2025-7960 Moyenne · 6,4
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.39 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization…

Versions affectées

*-51.1.39

Correctif

Non indiqué

Publication

12/12/2025

CVE-2025-8489 Critique · 9,8
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 – 51.1.14 – Unauthenticated Privilege Escalation

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the…

Versions affectées

24.12.92-51.1.14

Correctif

51.1.35

Publication

30/10/2025

CVE-2025-6327 Critique · 9,8
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.36 – Unauthenticated Arbitrary File Upload

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and…

Versions affectées

*-51.1.36

Correctif

51.1.37

Publication

21/10/2025

CVE-2025-6325 Critique · 9,8
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.36 – Unauthenticated Privilege Escalation

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 51.1.36. This makes it possible for…

Versions affectées

*-51.1.36

Correctif

51.1.37

Publication

21/10/2025

CVE-2025-62889 Moyenne · 4,3
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.62 – Missing Authorization

The King Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 51.1.62. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-51.1.62

Correctif

51.1.63

Publication

18/08/2025

CVE-2025-62887 Moyenne · 6,4
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 51.1.62 – Authenticated (Contributor+) Stored Cross-Site Scripting

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.62 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-51.1.62

Correctif

51.1.63

Publication

18/08/2025

CVE-2025-30926 Moyenne · 4,3
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

King Addons for Elementor <= 24.12.58 – Missing Authorization

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-24.12.58

Correctif

24.12.59

Publication

27/03/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités