CVE detail
CVE-2026-15284
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, and including, 51.1.62 This is due to insufficient input sanitization in the add_to_submissions() function, which applies sanitize_text_field() (which preserves double-quote characters) before storing the value in post meta, combined with missing output escaping in the king_addons_submissions_custom_column_content() function, which concatenates the stored value into an HTML href attribute via admin_url() without wrapping the result in esc_url(). This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 10
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/349ba9de-69b3-42fb-aeba-c3a24280547f?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset?old_path=%2Fking-addons/tags/51.1.62&new_path=%2Fking-addons/tags/51.1.63plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AMNo excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM- https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/View_Submissions_Pro.php#L305plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/Upload_Email_File.php#L261plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.62/includes/widgets/Form_Builder/helpers/Create_Submission.php#L68plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/View_Submissions_Pro.php#L305plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/Upload_Email_File.php#L261plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/king-addons/tags/51.1.61/includes/widgets/Form_Builder/helpers/Create_Submission.php#L68plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 5:16 AM - Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)Wordfence
henticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8118 Patch Status Patched Published Jun 18, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Jack Taylor More Details > RTMKit SALESmanago & Leado
vendorwww.wordfence.comJun 25, 2026, 7:02 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14856CVSS 6.3 · Medium
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization…
- CVE-2026-65764CVSS 5.1 · Medium
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
- CVE-2026-15928CVSS 8.2 · High
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
- CVE-2026-17496CVSS 8.1 · High
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without…
- CVE-2026-15425CVSS 6.4 · Medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up…
- CVE-2026-57531CVSS 5.1 · Medium
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScrip…