logo

Critical Elementor Plugin Vulnerability Let Attackers Takeover WordPress Site Admin Control

ID: 53a89624-49fc-5fde-8ef8-6fb4d5659631

STIX ID: report--53a89624-49fc-5fde-8ef8-6fb4d5659631

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-03

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical vulnerability (CVE-2025-8489, CVSS 9.8) in King Addons for Elementor (versions 24.12.92 through 51.1.14) allows unauthenticated attackers to register admin accounts by manipulating the user_role field via admin-ajax.php, enabling full site takeover; the vendor released patched version 51.1.35 and Wordfence deployed rules after public disclosure, while active exploitation was observed with tens of thousands of blocked attempts and several attacker IPs identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.