Critical Elementor Plugin Vulnerability Let Attackers Takeover WordPress Site Admin Control
ID: 40a66588-f0c7-5e0a-9c61-a7b2d3285beb
STIX ID: report--40a66588-f0c7-5e0a-9c61-a7b2d3285beb
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated privilege-escalation vulnerability (CVE-2025-8489, CVSS 9.8) in the King Addons for Elementor WordPress plugin allows attackers to create administrator accounts via the plugin's registration AJAX handler; the vendor patched the flaw in version 51.1.35, but active exploitation was observed immediately after disclosure with Wordfence reporting over 48,400 blocked attempts—site owners should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
