CVE-2025-8489Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-29); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-29: 1Mentions · 2026-07-08: 1Mentions · 2026-08-05: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 1Technical Details · 2026-08-05: 104-2907-0808-05
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-291
Active Exploitation1
2026-07-081
General1
2026-08-051
Active Exploitation1
Full discourse3 posts
  • Sienna Web Designs@siennawebdesign
    General

    Critical #WordPress Vulnerability: Admin Takeover Risk https://blog.quttera.com/post/wordpress-cve-2025-8489-admin-takeover-vulnerability

    Post summary

    The post simply announces a critical WordPress vulnerability (CVE‑2025‑8489) without providing detailed technical data, exploitation evidence, or remediation information.

    0004050
    293 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    A critical security flaw impacting a WordPress plugin known as King Addons for Elementor has come under active exploitation in the wild. The vulnerability, CVE-2025-8489 (CVSS score: 9.8), is a case of privilege escalat... https://f.mtr.cool/wlcifzvwsh

    Post summary

    CVE-2025-8489 is a privilege escalation flaw in the King Addons for Elementor plugin, rated 9.8 CVSS, and is presently being actively exploited in the wild.

    0000087
    2.1K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Active Exploitation

    WordPress Security Alert: CVE-2025-8489 (Admin Takeover) https://nvd.nist.gov/vuln/detail/CVE-2025-8489 A critical flaw in the King Addons for Elementor plugin lets unauthenticated attackers create admin accounts — no login required. (The Hacker News) What’s the risk? 👉 Full website takeover 👉 Malware injection & webshell deployment 👉 Payment skimmers, redirects, SEO spam 👉 Total loss of customer trust & revenue Root cause: The plugin fails to validate user roles during registration, allowing attackers to assign themselves administrator privileges. Real-world impact: ⚠️ Exploited in the wild within days ⚠️ 48,000+ attack attempts observed (BleepingComputer) ⚠️ Thousands of WordPress sites exposed How to protect your site: ✅ Update immediately (patched ≥ 51.1.35) ✅ Audit users for rogue admin accounts ✅ Monitor /wp-admin/admin-ajax.php activity ✅ Deploy full perimeter security scanning 🔎 Detect hidden backdoors & privilege abuse early: https://quttera.com/wordpress-malware-scanner #WordPress #CyberSecurity #CVE #WooCommerce #Malware #Infosec

    Post summary

    The post announces that CVE-2025-8489 in the King Addons for Elementor plugin is actively exploited, resulting in admin takeover, and urges immediate patching.

    00000599
    40 followersView on X

Explore more