Skip to content

King Addons flaw lets anyone become WordPress admin

Securityaffairs.Co •Pierluigi Paganini • December 3, 2025

Hackers are exploiting a King Addons flaw (CVE-2025-8489) that lets anyone register and instantly gain admin privileges on WordPress sites. Hackers are exploiting a critical vulnerability, tracked as CVE-2025-8489 (CVSS score of 9.8), in the WordPress plugin King Addons for Elementor that allows unauthenticated users to create admin accounts via a registration privilege bug. King […]

Extracted Entities

Attack Types (1)

CVEs (1)

MITRE ATT&CK (1)

Platforms (2)