What is CVE-2026-14841?
This CVE describes a Reflected XSS vulnerability in the King Addons for Elementor WordPress plugin before version 51.1.76, where an unescaped user-supplied grid setting is reflected into an HTML attribute in an unauthenticated AJAX response. Attackers can exploit this to execute arbitrary JavaScript in a victim's browser by tricking them into loading a crafted link. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: Bu CVE, King Addons for Elementor WordPress plagininin 51.1.76-dan əvvəlki versiyalarında autentifikasiya olunmamış AJAX cavabında istifadəçi tərəfindən təqdim edilən grid parametrinin filtrdən keçirilməməsi səbəbindən yaranan əks olunmuş XSS zəifliyidir. Təcavüzkar bu zəiflikdən istifadə edərək, xüsusi hazırlanmış link vasitəsilə ziyarətçinin brauzerində ixtiyari JavaScript kodu icra edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the King Addons for Elementor plugin are affected by CVE-2026-14841?
This vulnerability affects versions of the plugin prior to 51.1.76.
What can an attacker achieve by successfully exploiting CVE-2026-14841?
By tricking a user into loading a crafted link, an attacker can execute arbitrary JavaScript in the victim's browser.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.