A critical privilege escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor WordPress plugin has been actively exploited by attackers. The flaw, present in versions 24.12.92 through 51.1.14, allows unauthenticated users to register as administrators by specifying the administrator role during the registration process via a crafted request to the admin-ajax.php endpoint. This vulnerability, discovered by Peter Thaleikis and patched in version 51.1.35 on September 25, 2025, affects over 10,000 active installations. Wordfence has reported blocking more than 48,400 exploit attempts since the public disclosure, with mass exploitation beginning in early November 2025. Attackers have used several IP addresses, with two being particularly active, to create rogue admin accounts and potentially seize control of vulnerable sites.
Successful exploitation enables attackers to upload malicious code, deliver malware, redirect visitors, or inject spam into compromised sites. Security researchers recommend that website owners upgrade to the patched version immediately and check for unauthorized administrator accounts as a sign of compromise. Wordfence has provided a list of offensive IP addresses for administrators to monitor in their logs. The incident highlights the ongoing risk posed by third-party WordPress plugins and the importance of timely patching and monitoring for suspicious activity.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
By early December, Wordfence disclosed that it had blocked more than 48,400 attempts to exploit CVE-2025-8489 since October 31. The company also published indicators of compromise, including attacker IP addresses, and warned site owners to audit for suspicious administrator accounts.
Exploit activity against vulnerable King Addons installations surged around November 9–10, with Wordfence reporting this as the main peak period. Two IP addresses were said to account for most of the observed attack volume.
Threat actors started exploiting CVE-2025-8489 to create rogue administrator accounts on vulnerable WordPress sites via crafted admin-ajax.php requests. Wordfence said it observed attacks beginning on October 31, 2025.
CVE-2025-8489, a critical privilege-escalation flaw in King Addons for Elementor, was publicly disclosed, revealing that crafted AJAX registration requests could assign the administrator role. Reporting indicates exploitation began one day after this disclosure.
The King Addons for Elementor plugin vendor released a fix for CVE-2025-8489 in version 51.1.35, addressing an improper role restriction issue that let unauthenticated users register as administrators. Affected versions were reported as 24.12.92 through 51.1.14.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.