ThreatCluster

Critical King Addons Vulnerability Allows Unauthorized WordPress Admin Access

First seen 4 Dec 2025, 05:43 UTC Securityaffairs.CoSecurityaffairs 100% similarity 25

Article Content

Browse articles
ThreatCluster

A vulnerability in the King Addons for Elementor WordPress plugin, tracked as CVE-2025-8489, allows unauthenticated users to register and gain admin privileges on affected sites. This flaw, with a CVSS score of 9.8, is currently being exploited by hackers, including a group linked to Iran known as MuddyWater. Site administrators are urged to take immediate action to secure their installations.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story