Skip to content
ThreatCluster

Critical King Addons Vulnerability Allows Unauthorized WordPress Admin Access

First seen 4 Dec 2025, 05:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A vulnerability in the King Addons for Elementor WordPress plugin, tracked as CVE-2025-8489, allows unauthenticated users to register and gain admin privileges on affected sites. This flaw, with a CVSS score of 9.8, is currently being exploited by hackers, including a group linked to Iran known as MuddyWater. Site administrators are urged to take immediate action to secure their installations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 199d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track MuddyWater and CVE-2025-8489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed