CVE-2026-14841: Unknown King Addons For Elementor

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.

Affected products

  • Unknown King Addons For Elementor: before 51.1.76 (fixed in 51.1.76)

Published 2026-08-02. Last modified 2026-08-26.