logo

Critical Elementor Plugin Vulnerability Let Attackers Takeover WordPress Site Admin Control

ID: 40a66588-f0c7-5e0a-9c61-a7b2d3285beb

STIX ID: report--40a66588-f0c7-5e0a-9c61-a7b2d3285beb

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical unauthenticated privilege-escalation vulnerability (CVE-2025-8489, CVSS 9.8) in the King Addons for Elementor WordPress plugin allows attackers to create administrator accounts via the plugin's registration AJAX handler; the vendor patched the flaw in version 51.1.35, but active exploitation was observed immediately after disclosure with Wordfence reporting over 48,400 blocked attempts—site owners should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.