Vulnerability Management, Patch/Configuration Management

Critical King Addons flaw under attack

(Credit: Bilal Ulker – stock.adobe.com)

Numerous WordPress sites with the King Addons for Elementor plugin versions 24.12.92 to 51.1.14 could be compromised in attacks involving a recently addressed critical privilege escalation vulnerability, tracked as CVE-2025-8489, which have been underway since the end of October, Security Affairs reports.

More than 48,400 attempted exploits have already been thwarted by Wordfence, which noted a surge in intrusions leveraging the flaw beginning Nov. 9. Obtaining complete admin privileges following vulnerability abuse could facilitate total site takeovers, malicious code uploads, malware delivery, illicit site redirections, and spam injections, according to Wordfence, which noted that most of the attacks originated from IP addresses 45.61.157.120 and 2602:fa59:3:424::1.

"Even if you have already received a firewall rule for this issue we urge you to ensure that your site is updated to at least version 51.1.35 in order to maintain normal functionality," Wordfence said.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds