← Back to browse · API

CVE-2025-8489

Severity
CRITICAL
CVSS
9.8
EPSS
0.0927
Risk score
42.44
CISA KEV
No
PoC
No
Published
2025-10-31
Modified
2025-12-01
First seen
2026-08-07
Aliases
EUVD-2025-37306, GHSA-Q9WG-XWHC-4J78
Products
kingaddons:King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor * ≤51.1.14
Sources
euvd EUVD-2025-37306

Description

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

References