Numerous WordPress sites with the King Addons for Elementor plugin versions 24.12.92 to 51.1.14 could be compromised in attacks involving a recently addressed critical privilege escalation vulnerability, tracked as CVE-2025-8489, which have been underway since the end of October, Security Affairs reports.More than 48,400 attempted exploits have already been thwarted by Wordfence, which noted a surge in intrusions leveraging the flaw beginning Nov. 9. Obtaining complete admin privileges following vulnerability abuse could facilitate total site takeovers, malicious code uploads, malware delivery, illicit site redirections, and spam injections, according to Wordfence, which noted that most of the attacks originated from IP addresses 45.61.157.120 and 2602:fa59:3:424::1."Even if you have already received a firewall rule for this issue we urge you to ensure that your site is updated to at least version 51.1.35 in order to maintain normal functionality," Wordfence said.
Vulnerability Management, Patch/Configuration Management
Critical King Addons flaw under attack
(Credit: Bilal Ulker – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
