Exploitation of CVE-2025-8489 in King Addons for Elementor Plugin

Exploitation of CVE-2025-8489 in King Addons for Elementor Plugin

First seen 5 Dec 2025, 01:41 UTC BleepingcomputerScworldSocprime 85% similarity 53.7

Article Content

Browse articles
ThreatCluster

A critical privilege escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor plugin for WordPress is being actively exploited, allowing attackers to gain administrative permissions. The attacks began shortly after the vulnerability was disclosed, with over 48,400 exploit attempts blocked by Wordfence since November 9, 2025.

ThreatCluster AI How this analysis works

Community

Browse all →