HomeSecurityKing Addons for Elementor: Critical vulnerability in WordPress plugin

King Addons for Elementor: Critical vulnerability in WordPress plugin

A new serious threat is shaking up the WordPress, as security researchers have discovered a dangerous vulnerability in the popular King Addons for Elementor plugin, which is used on thousands of installations. The flaw, documented as CVE-2025-8489, allows unauthorized attackers to create accounts with full administrator privileges — a possibility that could lead to a complete takeover of a website.

King Addons for Elementor: Critical vulnerability in WordPress plugin

The plugin has over 10,000 active installations, underscoring the scale of the threat. According to the researchers, versions from 12/24/92 to 1/51/14 are vulnerable, and the issue has already been the focus of intense exploitation by cybercriminals.

How the vulnerability works and why it's so dangerous

The problem lies in the way the add-on handles new user registration. Unlike properly implemented registration features, King Addons' mechanism does not adequately restrict user rights during account creation.

See also: Vulnerabilities in Picklescan allow malicious PyTorch models to bypass checks

This means that an attacker can make a request to WordPress via the admin-ajax.php endpoint , setting the user_role to “administrator” field . Without any authentication, the system accepts the request and creates a new account with full access.

With such a click, the attacker gains complete control of the website and can:

  • installs malicious plugins and themes with backdoors
  • modifies or deletes content
  • introduces spam, phishing material or malware
  • redirects visitors to harmful websites
  • creates additional accounts for permanent access

CVE-2025-8489 is rated 9.8/10 on CVSS (Critical), reflecting the severity of the threat and ease of exploitation.

King Addons for Elementor: Critical vulnerability in WordPress plugin

Repairs and action by security companies

The plugin creator released update version 51.1.35 on September 25, 2025, fixing the critical bug. However, the exploit was already in place before users had time to update.

See also: OpenVPN: Vulnerabilities allow DoS and bypass of security mechanisms

Wordfence , one of the leading companies in the WordPress security space, added a firewall rule for Premium, Care, and Response users on August 4 , 2025, while the same protection was given to free users on September 3.

Despite the measures, attacks escalated after the vulnerability was publicly disclosed on October 30, 2025.

Barrage of attacks: Thousands of exploitation attempts in a few days

According to Wordfence, its firewall has already blocked over 48,400 exploit attempts, peaking on November 9th and 10th, when there was a rapid increase in malicious activity.

Certain IP addresses emerged as primary sources of attacks, including:

  • 45.61.157.120
  • 2602:fa59:3:424::1

Each of these was responsible for tens of thousands of requests attempting to create administrator accounts on vulnerable websites.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Researchers warn that the attacks will likely continue for weeks or even months, as the exploit is simple and very effective.

See also: Vulnerability in Microsoft Azure API Management bypasses administrator restrictions

King Addons for Elementor: Critical vulnerability in WordPress plugin

What website owners should do immediately

Administrators using King Addons for Elementor are urged to immediately take the following steps:

  1. Update the plugin to version 51.1.35 or later.
  2. Check for suspicious administrator accounts, especially those you don't recognize.
  3. Review logs for connection attempts or requests from IPs identified as dangerous.
  4. Check content, plugins, and themes for unauthorized changes.

Those who suspect their website has been compromised are urged to immediately seek help for cleanup and restoration.

The broader message: Plugin security is not a given

The King Addons case is a reminder that even widely used plugins can become gateways to serious breaches. With millions of websites relying on third-party plugins, keeping them up -to-date, using reliable security tools, and regularly auditing your system are essential steps to protect yourself.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS