Critical flaw in WordPress add-on for Elementor exploited in attacks
ID: 6946e1d0-f8ee-5361-9f98-5f0b9ea224f7
STIX ID: report--6946e1d0-f8ee-5361-9f98-5f0b9ea224f7
Feed Name: Bleeping Computer
A critical privilege-escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor WordPress plugin has been actively exploited to create rogue administrator accounts via crafted admin-ajax.php requests; Wordfence blocked over 48,400 attempts with two IPs responsible for most activity. The report also describes a separate critical RCE vulnerability (CVE-2025-13486) in Advanced Custom Fields:Extended impacting ~100,000 sites; both vendors released patches and site owners are urged to upgrade or disable affected plugins and check logs for new admin accounts or known malicious IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
