CVE-2025-30926

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 862

Summary

CVE-2025-30926 is a critical security vulnerability affecting King Addons for Elementor, a popular plugin used on KingAddons.com. The issue involves a missing authorization check that allows unauthenticated users to gain unauthorized access to certain functionalities of the plugin. This vulnerability can potentially lead to data theft or unintended modifications, posing a significant risk to websites utilizing this plugin from version n/a up to 24.12.58. Immediate patching is strongly advised to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share