King Addons for Elementor privilege escalation flaw (CVE-2025-8489, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
Active exploitation of CVE-2025-8489 in King Addons for Elementor creates administrative takeover risk for susceptible WordPress sites. The flaw lets unauthenticated attackers register as administrator through a crafted request to /wp-admin/admin-ajax.php. It affects versions 24.12.92 through 51.1.14 and was fixed in 51.1.35. Wordfence says it has already blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Related Happenings
RondoDox botnet exploitation of XWiki CVE-2025-24893
Malware Activity
First: 15.11.2025 18:35
Last: 15.11.2025 18:35
Sources 1
About this happening:
The **RondoDox** botnet has begun **targeting unpatched XWiki instances** through **CVE-2025-24893**, expanding its reach and putting vulnerable servers at risk of **botnet recrui...
RondoDox botnet exploitation of XWiki CVE-2025-24893
Malware ActivityAbout this happening: The **RondoDox** botnet has begun **targeting unpatched XWiki instances** through **CVE-2025-24893**, expanding its reach and putting vulnerable servers at risk of **botnet recrui...
Post SMTP CVE-2025-11833 exploitation wave
Exploitation Wave
First: 04.11.2025 23:46
Last: 04.11.2025 23:46
Sources 1
About this happening:
**CVE-2025-11833** in the **Post SMTP** WordPress plugin is being actively exploited to hijack administrator accounts, putting **more than 400,000 sites** at risk of **full site c...
Post SMTP CVE-2025-11833 exploitation wave
Exploitation WaveAbout this happening: **CVE-2025-11833** in the **Post SMTP** WordPress plugin is being actively exploited to hijack administrator accounts, putting **more than 400,000 sites** at risk of **full site c...
WordPress plugin exploitation wave (GutenKit and Hunk Companion)
Exploitation Wave
First: 24.10.2025 22:28
Last: 24.10.2025 22:28
Sources 1
About this happening:
**WordPress** sites are facing a broad **exploitation wave** against **GutenKit** and **Hunk Companion** plugin flaws, with **Wordfence** blocking **8.7 million attack attempts**...
WordPress plugin exploitation wave (GutenKit and Hunk Companion)
Exploitation WaveAbout this happening: **WordPress** sites are facing a broad **exploitation wave** against **GutenKit** and **Hunk Companion** plugin flaws, with **Wordfence** blocking **8.7 million attack attempts**...
CISA KEV addition for Smartbedded Meteobridge CVE-2025-4008
Public Sector Action
First: 03.10.2025 11:23
Last: 03.10.2025 11:23
Sources 1
About this happening:
CISA added **CVE-2025-4008** in **Smartbedded Meteobridge** to the **KEV catalog**, signaling **active exploitation** and requiring **FCEB agencies** to apply updates by **October...
CISA KEV addition for Smartbedded Meteobridge CVE-2025-4008
Public Sector ActionAbout this happening: CISA added **CVE-2025-4008** in **Smartbedded Meteobridge** to the **KEV catalog**, signaling **active exploitation** and requiring **FCEB agencies** to apply updates by **October...
Timeline
-
03.12.2025 19:08 2 articles · 5mo ago
King Addons for Elementor patch release
Mitigation Patch UpdateKing Addons for Elementor maintainers released version 51.1.35 on September 25, 2025 to fix CVE-2025-8489, a critical privilege-escalation flaw affecting versions 24.12.92 through 51.1.14 that let unauthenticated attackers register as administrator.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 5mo ago
Early targeting of vulnerable WordPress sites
Exploitation ObservedAttackers may have begun targeting WordPress sites with King Addons for Elementor as early as October 31, 2025 by abusing crafted registration requests to /wp-admin/admin-ajax.php to assign the administrator role.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 1 articles · 5mo ago
Mass exploitation of King Addons for Elementor
Campaign Scope UpdateMass exploitation of CVE-2025-8489 against WordPress sites with King Addons for Elementor started on November 9, 2025, using the same role-abuse technique to obtain administrator privileges.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
-
03.12.2025 19:08 2 articles · 5mo ago
Wordfence active-exploitation disclosure
Initial DisclosureWordfence publicly reported active exploitation of CVE-2025-8489 in King Addons for Elementor, explained that handle_register_ajax() failed to restrict registration roles, and said it had blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 5mo ago
King Addons for Elementor patch release
Mitigation Patch UpdateKing Addons for Elementor maintainers released version 51.1.35 on September 25, 2025 to fix CVE-2025-8489, a critical privilege-escalation flaw affecting versions 24.12.92 through 51.1.14 that let unauthenticated attackers register as administrator.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 5mo ago
Early targeting of vulnerable WordPress sites
Exploitation ObservedAttackers may have begun targeting WordPress sites with King Addons for Elementor as early as October 31, 2025 by abusing crafted registration requests to /wp-admin/admin-ajax.php to assign the administrator role.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 5mo ago
Wordfence active-exploitation disclosure
Initial DisclosureWordfence publicly reported active exploitation of CVE-2025-8489 in King Addons for Elementor, explained that handle_register_ajax() failed to restrict registration roles, and said it had blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31