King Addons for Elementor privilege escalation flaw (CVE-2025-8489, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
Active exploitation of CVE-2025-8489 in King Addons for Elementor creates administrative takeover risk for susceptible WordPress sites. The flaw lets unauthenticated attackers register as administrator through a crafted request to /wp-admin/admin-ajax.php. It affects versions 24.12.92 through 51.1.14 and was fixed in 51.1.35. Wordfence says it has already blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Related Happenings
RondoDox botnet exploitation of XWiki CVE-2025-24893
Malware Activity
H score33
First: 15.11.2025 18:35
Last: 15.11.2025 18:35
Sources 1
About this happening:
The RondoDox botnet has begun targeting unpatched XWiki instances through CVE-2025-24893, expanding its reach and putting vulnerable servers at risk of botnet recrui...
RondoDox botnet exploitation of XWiki CVE-2025-24893
Malware ActivityAbout this happening: The RondoDox botnet has begun targeting unpatched XWiki instances through CVE-2025-24893, expanding its reach and putting vulnerable servers at risk of botnet recrui...
Post SMTP CVE-2025-11833 exploitation wave
Exploitation Wave
H score74
First: 04.11.2025 23:46
Last: 04.11.2025 23:46
Sources 1
About this happening:
CVE-2025-11833 in the Post SMTP WordPress plugin is being actively exploited to hijack administrator accounts, putting more than 400,000 sites at risk of full site c...
Post SMTP CVE-2025-11833 exploitation wave
Exploitation WaveAbout this happening: CVE-2025-11833 in the Post SMTP WordPress plugin is being actively exploited to hijack administrator accounts, putting more than 400,000 sites at risk of full site c...
WordPress plugin exploitation wave (GutenKit and Hunk Companion)
Exploitation Wave
H score55
First: 24.10.2025 22:28
Last: 24.10.2025 22:28
Sources 1
About this happening:
WordPress sites are facing a broad exploitation wave against GutenKit and Hunk Companion plugin flaws, with Wordfence blocking 8.7 million attack attempts...
WordPress plugin exploitation wave (GutenKit and Hunk Companion)
Exploitation WaveAbout this happening: WordPress sites are facing a broad exploitation wave against GutenKit and Hunk Companion plugin flaws, with Wordfence blocking 8.7 million attack attempts...
CISA KEV addition for Smartbedded Meteobridge CVE-2025-4008
Public Sector Action
H score36
First: 03.10.2025 11:23
Last: 03.10.2025 11:23
Sources 1
About this happening:
CISA added CVE-2025-4008 in Smartbedded Meteobridge to the KEV catalog, signaling active exploitation and requiring FCEB agencies to apply updates by October...
CISA KEV addition for Smartbedded Meteobridge CVE-2025-4008
Public Sector ActionAbout this happening: CISA added CVE-2025-4008 in Smartbedded Meteobridge to the KEV catalog, signaling active exploitation and requiring FCEB agencies to apply updates by October...
Timeline
-
03.12.2025 19:08 2 articles · 7mo ago
King Addons for Elementor patch release
Mitigation Patch UpdateKing Addons for Elementor maintainers released version 51.1.35 on September 25, 2025 to fix CVE-2025-8489, a critical privilege-escalation flaw affecting versions 24.12.92 through 51.1.14 that let unauthenticated attackers register as administrator.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 7mo ago
Early targeting of vulnerable WordPress sites
Exploitation ObservedAttackers may have begun targeting WordPress sites with King Addons for Elementor as early as October 31, 2025 by abusing crafted registration requests to /wp-admin/admin-ajax.php to assign the administrator role.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 1 articles · 7mo ago
Mass exploitation of King Addons for Elementor
Campaign Scope UpdateMass exploitation of CVE-2025-8489 against WordPress sites with King Addons for Elementor started on November 9, 2025, using the same role-abuse technique to obtain administrator privileges.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
-
03.12.2025 19:08 2 articles · 7mo ago
Wordfence active-exploitation disclosure
Initial DisclosureWordfence publicly reported active exploitation of CVE-2025-8489 in King Addons for Elementor, explained that handle_register_ajax() failed to restrict registration roles, and said it had blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 7mo ago
King Addons for Elementor patch release
Mitigation Patch UpdateKing Addons for Elementor maintainers released version 51.1.35 on September 25, 2025 to fix CVE-2025-8489, a critical privilege-escalation flaw affecting versions 24.12.92 through 51.1.14 that let unauthenticated attackers register as administrator.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 7mo ago
Early targeting of vulnerable WordPress sites
Exploitation ObservedAttackers may have begun targeting WordPress sites with King Addons for Elementor as early as October 31, 2025 by abusing crafted registration requests to /wp-admin/admin-ajax.php to assign the administrator role.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31
-
03.12.2025 19:08 2 articles · 7mo ago
Wordfence active-exploitation disclosure
Initial DisclosureWordfence publicly reported active exploitation of CVE-2025-8489 in King Addons for Elementor, explained that handle_register_ajax() failed to restrict registration roles, and said it had blocked over 48,400 exploit attempts since public disclosure in late October 2025.
Show sources
- WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts — thehackernews.com — 03.12.2025 19:08
- Critical flaw in WordPress add-on for Elementor exploited in attacks — www.bleepingcomputer.com — 03.12.2025 23:31