CVE-2025-6327: WordPress King Addons for Elementor plugin <= 51.1.36 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a Web Server.This issue affects King Addons for Elementor: from n/a through <= 51.1.36.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6327?
CVE-2025-6327 is classified as a critical severity vulnerability due to its potential for arbitrary file upload, allowing attackers to upload malicious files.
How do I fix CVE-2025-6327?
To fix CVE-2025-6327, update King Addons for Elementor to the latest version that is greater than 51.1.36 immediately.
What type of vulnerability is CVE-2025-6327?
CVE-2025-6327 is an Unrestricted Upload of File with Dangerous Type vulnerability.
Which versions of King Addons for Elementor are affected by CVE-2025-6327?
CVE-2025-6327 affects all versions of King Addons for Elementor up to and including version 51.1.36.
What can attackers do with CVE-2025-6327?
Attackers can exploit CVE-2025-6327 to upload a web shell to the server, potentially leading to full system compromise.