CVE-2025-8489: King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8489?
CVE-2025-8489 is considered a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-8489?
To mitigate CVE-2025-8489, update the King Addons for Elementor plugin to version 51.1.35 or higher.
What causes CVE-2025-8489?
CVE-2025-8489 is caused by the plugin failing to properly restrict user registration roles.
Which versions of King Addons for Elementor are affected by CVE-2025-8489?
CVE-2025-8489 affects versions from 24.12.92 to 51.1.14 of the King Addons for Elementor plugin.
Who should be concerned about CVE-2025-8489?
WordPress users utilizing the vulnerable versions of the King Addons for Elementor plugin should prioritize addressing CVE-2025-8489.