In a sharp warning to WordPress site administrators worldwide, security researchers have confirmed active exploitation of a critical vulnerability in the popular plugin King Addons for Elementor. The flaw — tracked as CVE-2025-8489 — enables unauthenticated attackers to register themselves as administrators, potentially giving them full control over vulnerable sites. With over 10,000 active installations of the plugin, the security community is urging immediate action.

What Went Wrong: Privilege Escalation Made Easy

The vulnerability resides in the plugin’s registration process, specifically within a function called handle_register_ajax(). Under a properly secured system, new user registrations should default to low-privilege roles (like “Subscriber”). However, due to improper restrictions in the code, attackers can bypass these safeguards. By submitting a crafted HTTP request to the /wp-admin/admin-ajax.php endpoint with the parameter user_role=administrator, they can create admin-level accounts — all without authentication.

The weakness spans versions from 24.12.92 up to 51.1.14 of the plugin. The developers addressed the issue in version 51.1.35, released on September 25, 2025.

Scope of Impact and Real-World Exploitation

The significance of this flaw becomes starkly evident when looking at exploitation data. The security firm Wordfence — one of the first to raise the alarm — reports blocking over 48,400 exploit attempts since the vulnerability’s public disclosure. Attack patterns suggest that abuse began almost immediately after the disclosure, with evidence pointing to exploitation activity as early as October 31, 2025, and mass attacks picking up pace around November 9.

Once an attacker acquires administrator-level access, the consequences could be severe. They might upload malicious plugins or themes, deploy backdoors, inject spam, or redirect site visitors to phishing or malware-hosting domains — effectively turning a benign website into a dangerous platform.

Compounding the danger is the fact that many affected WordPress sites remain unpatched. Some administrators may be unaware of the update, or may not have prioritized the patching process — leaving their sites exposed to takeover.

Broader Context: WordPress Plugin Ecosystem Under Fire

This incident is part of a worrying trend: attackers increasingly focus on plugins for widely used frameworks like WordPress. Plugins — especially those used by thousands of sites — offer a broad attack surface: a single vulnerability can potentially compromise tens of thousands of websites. Security analysts have repeatedly warned about the risks of using poorly maintained or insecure add-ons, especially for site-builder plugins like King Addons.

Also notable is that this is not the only path to compromise recently observed in WordPress-based sites. Other plugins and themes have been flagged for similar critical vulnerabilities, prompting a renewed emphasis on patch management and plugin hygiene across the ecosystem

What Site Owners Should Do Right Now

  • Update Immediately: If you are using King Addons for Elementor, make sure it is updated to version 51.1.35 or later. This version contains the fix for the privilege escalation flaw.
  • Audit User Accounts: Review all existing user accounts for unauthorized admin users — especially those created recently.
  • Monitor Logs: Check server and access logs for suspicious registration requests or uploads, particularly to the /wp-admin/admin-ajax.php endpoint.
  • Harden WordPress Security Posture: Consider disabling unnecessary registration functionality, using a Web Application Firewall (WAF), enforcing strong admin password policies, and restricting plugin usage to only those essential for your site.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *