THREAT OPS › Threat News › [NVD] CVE-2026-84896 (MEDIUM 6.8) — The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the a
[NVD] CVE-2026-84896 (MEDIUM 6.8) — The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the a
CVE-2026-84896 CVSS: 6.8 MEDIUM Published: 2026-09-05T07:17:13.940
The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-84896cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84896