Threat actors are actively exploiting a critical vulnerability in King Addons for Elementor, a popular WordPress plugin, leading to potential full-site compromises. Over 50,000 exploit attempts have been observed since threat actors began targeting the CVE-2025-8489 flaw. #KingAddons #WordPressVulnerabilities
Keypoints
- The vulnerability CVE-2025-8489 allows unauthenticated privilege escalation on affected WordPress sites.
- It impacts versions of King Addons for Elementor from 24.12.92 up to 51.1.14 until patched in version 51.1.35.
- Threat actors have created significant attack campaigns, with around 50,000 exploit attempts recorded within a month.
- Successful exploitation permits attackers to grant themselves administrator privileges and fully control the website.
- Users should update to version 51.1.35 or newer to mitigate the risk of exploitation.
Read More: https://www.securityweek.com/critical-king-addons-vulnerability-exploited-to-hack-wordpress-sites/