Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Mar 22, 2026

King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder (`king-addons`), including severity, CVE references, affected versions, and patch status.

Known Records
8
High or Critical
3
Linked CVEs
8
Last Updated
Mar 22, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
8 records include a published patch path.
Severity Mix
3 critical and 0 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-13997
King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML...

Published
Mar 22, 2026
Patched Release
51.1.51
Affected Versions
Versions up to 51.1.49
Next Step
Update to 51.1.51 or newer if supported.
Plugin Medium Patched: No CVE-2025-7960
King Addons for Elementor <= 51.1.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Slider, Pricing Calculator, and Image Accordion widgets in all versions up to, and including, 51.1.39 due to insufficient input sanitization and output escapin...

Published
Dec 12, 2025
Patched Release
Not published
Affected Versions
Versions up to 51.1.39
Next Step
Open the full report for remediation notes and references.
Plugin Critical Patched: Yes CVE-2025-8489
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. Th...

Published
Oct 30, 2025
Patched Release
51.1.35
Affected Versions
24.12.92 through 51.1.14
Next Step
Update to 51.1.35 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-6327
King Addons for Elementor <= 51.1.36 - Unauthenticated Arbitrary File Upload

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 51.1.36. This makes it possible f...

Published
Oct 21, 2025
Patched Release
51.1.37
Affected Versions
Versions up to 51.1.36
Next Step
Update to 51.1.37 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-6325
King Addons for Elementor <= 51.1.36 - Unauthenticated Privilege Escalation

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 51.1.36. This makes it possible for unauthenticated attackers to regist...

Published
Oct 21, 2025
Patched Release
51.1.37
Affected Versions
Versions up to 51.1.36
Next Step
Update to 51.1.37 or newer if supported.
Plugin Medium Patched: No CVE-2025-62889
King Addons for Elementor <= 51.1.49 - Missing Authorization

The King Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 51.1.49. This makes it possible for authenticated attackers, with contributor-level access and above, to perfo...

Published
Aug 18, 2025
Patched Release
Not published
Affected Versions
Versions up to 51.1.49
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: No CVE-2025-62887
King Addons for Elementor <= 51.1.37 - Authenticated (Contributor+) Stored Cross-Site Scripting

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 51.1.37 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

Published
Aug 18, 2025
Patched Release
Not published
Affected Versions
Versions up to 51.1.37
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-30926
King Addons for Elementor <= 24.12.58 - Missing Authorization

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 24.12.58. This makes it possible for authe...

Published
Mar 27, 2025
Patched Release
24.12.59
Affected Versions
Versions up to 24.12.58
Next Step
Update to 24.12.59 or newer if supported.