King Addons flaw lets anyone become WordPress admin
ID: 900a8a65-0adf-59c5-a4cc-8f1df0d3bc74
STIX ID: report--900a8a65-0adf-59c5-a4cc-8f1df0d3bc74
Feed Name: Security Affairs
Threat Score
A critical vulnerability (CVE-2025-8489, CVSS 9.8) in the King Addons for Elementor plugin allows unauthenticated attackers to register as administrators via admin-ajax.php, enabling complete site takeover; Wordfence reports active exploitation with ~48,400 blocked attempts and recommends updating to version 51.1.35 and checking for malicious admin accounts and suspicious requests (notable attacking IPs are listed).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
