CVE-2026-12349

MEDIUM

Premium Addons for KingComposer <= 1.1.1 - Unauthenticated Sidebar Modification

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-12349. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-12349, a missing authorization vulnerability in the Premium Addons for KingComposer WordPress plugin (versions ≤1.1.1). The code includes placeholder logic for target probing but lacks actual exploit implementation or payload delivery.

Description

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX handlers, both of which are exposed through wp_ajax_nopriv_* hooks and write directly to the octagon_custom_sidebar option via update_option(). This makes it possible for unauthenticated attackers to create arbitrary custom widget areas or delete existing custom sidebars, which can cause widgets assigned to those areas to silently lose their registration and stop rendering.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-12349_the_premium_addons.py

This repository contains an auto-generated stub module for CVE-2026-12349, a missing authorization vulnerability in the Premium Addons for KingComposer WordPress plugin (versions ≤1.1.1). The code includes placeholder logic for target probing but lacks actual exploit implementation or payload delivery.

Classification
Stub 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Premium Addons for KingComposer WordPress plugin (versions up to and including 1.1.1)
No auth needed
Prerequisites: Target must be running a vulnerable version of the Premium Addons for KingComposer plugin · Network access to the WordPress instance (HTTP/HTTPS)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
octagonwebstudio/Premium Addons for KingComposer < 1.1.1
Published Jun 30, 2026
Tracked Since Jun 30, 2026