Critical Elementor Plugin Vulnerability Let Attackers Takeover WordPress Site Admin Control
A critical security flaw has been identified in the "King Addons for Elementor" WordPress plugin, putting numerous websites at risk. The vulnerability, designated as CVE-2025-8489, enables unauthenticated attackers to register new accounts with…
A critical security flaw has been identified in the "King Addons for Elementor" WordPress plugin, putting numerous websites at risk. The vulnerability, designated as CVE-2025-8489, enables unauthenticated attackers to register new accounts with administrative privileges by exploiting an insecure registration function within the plugin.
This vulnerability impacts plugin versions 24.12.92 to 51.1.14, which are currently installed on over 10,000 active sites. The flaw stems from inadequate restrictions on user roles during the registration process, allowing attackers to create admin-level accounts without prior access.
Attackers can execute this exploit by crafting a request to the WordPress admin-ajax.php endpoint, setting the "user_role" field to "administrator". This grants them full control over the affected website, including the ability to install malicious plugins, modify content, and redirect users to harmful sites.
Attribute Details
Vulnerability Name King Addons for Elementor - Unauthenticated Privilege Escalation
CVE ID CVE-2025-8489
CVSS Rating 9.8 (Critical)
Vulnerability Type Unauthenticated Privilege Escalation
A critical security flaw has been identified in the "King Addons for Elementor" WordPress plugin, putting numerous websites at risk.
Affected Plugin King Addons for Elementor
The plugin developer has released a patched version, 51.1.35, as of September 25, 2025. Wordfence implemented a firewall rule to prevent attacks for Premium, Care, and Response customers on August 4, 2025, extending this protection to free users on September 3, 2025.
Despite these measures, active exploitation began shortly after the vulnerability was publicly disclosed on October 30, 2025. Wordfence reports over 48,400 blocked exploit attempts, with a notable increase in attack traffic on November 9 and 10. Key IP addresses associated with these attacks include 45.61.157.120 and 2602:fa59:3:424::1.
IP Address Blocked Requests
45.61.157.120 28,900+
2602:fa59:3:424::1 16,900+
182.8.226.228 300+
138.199.21.230 100+
206.238.221.25 100+
Update to version 51.1.35 or later immediately. Check for unknown or suspicious administrator accounts. Review server and access logs for requests from known attacking IPs. Monitor for unusual changes to content, plugins, or themes.
Site owners suspecting compromise should seek professional incident response and cleanup services promptly.
Based on reporting by Cyber Security News.
