Critical Elementor Plugin Vulnerability Let Attackers Takeover WordPress Site Admin Control
ID: 53a89624-49fc-5fde-8ef8-6fb4d5659631
STIX ID: report--53a89624-49fc-5fde-8ef8-6fb4d5659631
Feed Name: cybersecurityNews.com
Threat Score
A critical vulnerability (CVE-2025-8489, CVSS 9.8) in King Addons for Elementor (versions 24.12.92 through 51.1.14) allows unauthenticated attackers to register admin accounts by manipulating the user_role field via admin-ajax.php, enabling full site takeover; the vendor released patched version 51.1.35 and Wordfence deployed rules after public disclosure, while active exploitation was observed with tens of thousands of blocked attempts and several attacker IPs identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
