Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Elementor Plugin Flaw Allows Attackers to Seize WordPress Admin Control

## Cybersecurity: Vulnerability in King Addons for Elementor WordPress Plugin

Cybersecurity: Vulnerability in King Addons for Elementor WordPress Plugin

A significant privilege escalation vulnerability has been identified in the King Addons for Elementor WordPress plugin, potentially compromising thousands of websites. The flaw is tracked as CVE-2025-8489 and has a critical CVSS score of 9.8. This vulnerability allows unauthenticated attackers to gain administrator-level privileges, providing them complete control over affected sites.

CVE ID: CVE-2025-8489 CVSS Score: 9.8 (Critical) Vulnerability Type: Unauthenticated Privilege Escalation Affected Versions: 24.12.92 – 51.1.14

The vulnerability exists in King Addons for Elementor, a plugin with over 10,000 active installations, affecting versions 24.12.92 through 51.1.14. The issue arises from improper role restrictions during user registration. The plugin fails to validate user-specified roles, allowing attackers to register as administrators.

The vendor released a patched version, 51.1.35, on September 25, 2025, following initial reports on July 24, 2025.

The flaw is tracked as CVE-2025-8489 and has a critical CVSS score of 9.8.
Brooke Sanders · Thehackingpost

The vulnerability involves the handle_register_ajax() function, which accepts a user_role parameter from POST requests without proper authorization checks. Attackers can exploit this by specifying "administrator" as their role.

Exploitation of this vulnerability was disclosed on October 30, 2025, with attacks commencing on October 31, 2025. The Wordfence Firewall has blocked over 48,400 exploit attempts, with significant attack activity noted on November 9-10, 2025. Premium Wordfence users received protection on August 4, 2025, with free users protected by September 3, 2025.

Analysis indicates a coordinated attack campaign, with the IP address 45.61.157.120 responsible for over 28,900 blocked requests, and 2602:fa59:3:424::1 for an additional 16,900 attempts.

Advertisement

Administrators using the King Addons for Elementor plugin should upgrade to version 51.1.35 immediately. It is advisable to monitor for suspicious administrator accounts created during the exploitation period and review server logs for requests from identified malicious IP addresses.

Sites running vulnerable versions should assume potential compromise and conduct comprehensive security audits.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories