Skip to content
Critical King Addons flaw under attack

Critical King Addons flaw under attack

Scworld December 5, 2025

Numerous WordPress sites with the King Addons for Elementor plugin versions 24.12.92 to 51.1.14 could be compromised in attacks involving a recently addressed critical privilege escalation vulnerability, tracked as CVE-2025-8489, which have been underway since the end of October, Security Affairs reports.

More than 48,400 attempted exploits have already been thwarted by Wordfence, which noted a surge in intrusions leveraging the flaw beginning Nov. 9. Obtaining complete admin privileges following vulnerability abuse could facilitate total site takeovers, malicious code uploads, malware delivery, illicit site redirections, and spam injections, according to Wordfence, which noted that most of the attacks originated from IP addresses 45.61.157.120 and 2602:fa59:3:424::1.

"Even if you have already received a firewall rule for this issue we urge you to ensure that your site is updated to at least version 51.1.35 in order to maintain normal functionality," Wordfence said.

Extracted Entities

Attack Types (1)

CVEs (1)

IP Addresses (1)

IPv6 Addresses (1)