
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8489 is a critical privilege escalation vulnerability in the King Addons for Elementor WordPress plugin that allows unauthenticated attackers to register administrator-level user accounts. The flaw affects plugin versions 24.12.92 through 51.1.14 and was published on October 31, 2025, with the assigner being Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is improper privilege management (CWE-269): the plugin's Login/Register Form widget does not properly restrict which user roles can be selected during registration, allowing any user — including unauthenticated visitors — to specify the administrator role when submitting a registration request. The vulnerable code path resides in Login_Register_Form_Ajax.php (e.g., line 353 in tag 24.12.93 and line 160 in tag 51.1.35), where the role parameter passed by the client is accepted without server-side validation against an allowlist of safe roles. No authentication, special privileges, or user interaction is required to exploit this flaw (Wordfence, ZeroPath).
Successful exploitation grants an attacker full WordPress administrator access, enabling arbitrary code execution, installation of malicious plugins or backdoors, data theft, website defacement, and complete site takeover. Because WordPress administrators can upload and execute PHP code, this vulnerability effectively provides remote code execution on the underlying server. All sites running the affected plugin versions — estimated at over 10,000 active installations — are at risk of full compromise, including potential lateral movement to other services sharing the same hosting environment (Wordfence, BleepingComputer, Security Affairs).
This vulnerability is being actively exploited in the wild, with Wordfence confirming ongoing attacks as of December 2025 (Wordfence). A Metasploit module (wp_king_addons_privilege_escalation) was added to the Rapid7 Metasploit Framework on December 10, 2025, significantly lowering the barrier to exploitation (Metasploit, Rapid7 Blog). Public proof-of-concept details were also published in early November 2025 (CryptoBivash). The EPSS score is approximately 0.052% (0.000520), and no specific threat actor attribution has been reported. Qualys has added detection for this vulnerability (detection ID 733368). The vulnerability does not appear in the CISA KEV catalog at this time.
wp-admin/admin-ajax.php with a specific action parameter).role parameter to administrator. No authentication token or prior session is required./wp-admin/).wp-admin/admin-ajax.php with King Addons registration action parameters from unexpected or foreign IP addresses; new administrator user creation events in WordPress authentication logs (wp-login.php or database wp_users table).shell.php, cmd.php, or similar) in wp-content/uploads/, wp-content/plugins/, or wp-content/themes/ directories; unexpected modifications to wp-config.php.wp_users and wp_usermeta tables with wp_capabilities set to administrator and creation timestamps corresponding to suspicious activity windows.role=administrator in the POST body.bash, curl, wget, python) after the registration event (Wordfence, BleepingComputer).Immediately update the King Addons for Elementor plugin to version 51.1.35 or later, which contains the fix restricting user-selectable roles during registration (Wordfence). If an immediate update is not possible, temporarily disable the plugin to remove the attack surface. After patching, audit all WordPress administrator accounts for unauthorized entries and remove any suspicious users. Additionally, review website files and logs for signs of post-exploitation activity, implement two-factor authentication for all admin accounts, and consider deploying a WordPress-aware WAF (e.g., Wordfence) to detect and block exploitation attempts (Wordfence, Security Affairs).
Wordfence confirmed active exploitation in December 2025 and published a detailed advisory urging immediate patching (Wordfence). BleepingComputer, The Hacker News, Security Affairs, SecurityWeek, and SC World all covered the active exploitation, amplifying urgency across the security community (BleepingComputer, The Hacker News, SecurityWeek). Social media discussions on Reddit (r/SecOpsDaily), Mastodon (infosec.exchange), and Bluesky reflected widespread concern, with security practitioners urging site owners to patch immediately and audit admin accounts (Reddit). Rapid7 highlighted the addition of a Metasploit module in their December 12, 2025 wrap-up, noting the ease of exploitation (Rapid7 Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."