Description
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.
Problem types
CWE-269 Improper Privilege Management
Product status
* (semver)
Timeline
| 2025-10-30: | Disclosed |
Credits
Peter Thaleikis
References
www.wordfence.com/...-9a3b-4428-8624-26a1202fe3b0?source=cve
plugins.trac.wordpress.org/...m/Login_Register_Form_Ajax.php
plugins.trac.wordpress.org/...m/Login_Register_Form_Ajax.php