CVE-2025-6325 is an incorrect privilege assignment vulnerability in KingAddons.com King Addons for Elementor (plugin slug: king-addons) for WordPress. The issue affects versions through 51.1.36. Based on the available advisory text, the plugin improperly assigns privileges, which can allow a user to obtain capabilities beyond those intended by the application’s authorization model. Specific vulnerable functions or code paths are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, a detailed README, and a standalone Python 3 exploit script. It is not tied to a recognized exploitation framework and uses only Python standard-library modules. The script supports check, privesc, upload, and both modes; accepts a single URL or a target list; crawls site pages and sitemap candidates for leaked JavaScript nonce data; and processes multiple targets using a thread pool. It targets two King Addons for Elementor flaws. For CVE-2025-6325, it abuses the public WordPress AJAX registration action by providing the client-controlled value `user_role=administrator`, then attempts login and administrative-page verification. For CVE-2025-6327, it invokes the public upload action to place a PHP test file in the King Addons forms upload directory and requests the resulting URL to validate command execution via `id`. Results are displayed live and persisted to `results.tsv`; successful account or shell validations are also appended to `loot.txt`. The repository claims affected releases through 51.1.36 and a fix in 51.1.37, but notes that some later WordPress.org packages were retagged and that its confirmed vulnerable lab package was version 51.1.14. The provided content is truncated in the middle of exploit.py, so exact request-body fields, generated credential format, and the precise PHP payload text cannot be independently confirmed from the supplied source; the stated behavior is supported by the visible header and README.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.