CVE-2025-8489

🟠 Łataj w tym tygodniu

Błąd w wtyczce King Addons dla Elementor umożliwia nieautoryzowanym atakującym rejestrację jako administrator.

CVSS
9.8
EPSS
9.6%
Exploit
none
Vendor
Opis źródłowy (NVD)

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)9.6%
Opublikowano (NVD)2025-10-31 07:15:38 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje