Vulnerability Description
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quote characters) before storing the value in post meta, combined with missing output escaping in the king_addons_submissions_custom_column_content() function, which concatenates the stored value into an HTML href attribute via admin_url() without wrapping the result in esc_url(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/wid
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/wid
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/wid
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/wid
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/wid
- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/wid
- https://plugins.trac.wordpress.org/changeset/3537725/king-addons/tags/51.1.63/in
- https://plugins.trac.wordpress.org/changeset/3537725/king-addons/tags/51.1.63/in
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fking-addons/tags/51.1.6
- https://www.wordfence.com/threat-intel/vulnerabilities/id/349ba9de-69b3-42fb-aeb
FAQ
What is CVE-2026-15284?
CVE-2026-15284 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient i...
How severe is CVE-2026-15284?
CVE-2026-15284 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15284?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.