Critical King Addons Vulnerability Allows Unauthorized WordPress Admin Access
Article Content
Browse articles
A vulnerability in the King Addons for Elementor WordPress plugin, tracked as CVE-2025-8489, allows unauthenticated users to register and gain admin privileges on affected sites. This flaw, with a CVSS score of 9.8, is currently being exploited by hackers, including a group linked to Iran known as MuddyWater. Site administrators are urged to take immediate action to secure their installations.
Ask AI about this cluster
Answers cite the sources they use
Updated 199d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track MuddyWater and CVE-2025-8489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Iran's Ravin Academy Launches Largest Cyber Training Class Amid US-Iran Tensions Ravin Academy, an Iranian cybersecurity training firm, has announced its largest recruitment drive, seeking between 600 and 1,200 young Iranians for a free yearlong cybersecurity scholarship. This initiative occurs amid escalating cyberattacks attributed to Iran against US infrastructure. The US Treasury previously…