logo

King Addons flaw lets anyone become WordPress admin

ID: 900a8a65-0adf-59c5-a4cc-8f1df0d3bc74

STIX ID: report--900a8a65-0adf-59c5-a4cc-8f1df0d3bc74

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2025-12-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical vulnerability (CVE-2025-8489, CVSS 9.8) in the King Addons for Elementor plugin allows unauthenticated attackers to register as administrators via admin-ajax.php, enabling complete site takeover; Wordfence reports active exploitation with ~48,400 blocked attempts and recommends updating to version 51.1.35 and checking for malicious admin accounts and suspicious requests (notable attacking IPs are listed).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.