top of page
perceptive_background_267k.jpg

WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

Published:

3 December 2025 at 17:08:00

Alert date:

5 December 2025 at 08:03:23

Source:

thehackernews.com

Click to open the original link from this advisory

A critical security vulnerability (CVE-2025-8489) in the WordPress King Addons for Elementor plugin is being actively exploited in the wild. The flaw allows unauthenticated attackers to escalate privileges and grant themselves administrative access by simply specifying the administrator role during registration. This vulnerability has a CVSS score of 9.8, indicating its critical severity. The exploitation allows complete compromise of affected WordPress sites running the vulnerable plugin. Organizations using this plugin should immediately update or remove it to prevent unauthorized administrative access.

Technical details

Mitigation steps:

Affected products:

WordPress King Addons for Elementor

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page