External risk intelligence

King Addons for Elementor Unauthenticated Administrator Registration Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-8489

The vulnerability exists in a WordPress plugin that provides registration and login functionality. Because this feature is designed to be public-facing to allow user account creation on a website, the vulnerable interface is reachable over the public internet by design in its normal deployment.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in a WordPress plugin could allow unauthenticated attackers to gain administrator access to websites. The issue stems from improper role restrictions during user registration, potentially impacting any site using the affected plugin. The primary concern is confirming if this plugin is in use and understanding the potential exposure.

  • Unauthenticated users could become administrators.
  • Protects against unauthorized website control.
  • Confirm use; assess potential exposure.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by leveraging the plugin's user registration feature to create an administrator account without needing any prior authentication. This allows them to gain full control over the affected WordPress site.

  • Unauthenticated users can access the registration function.
  • The plugin improperly restricts user registration roles.
  • Attackers gain administrator access and site control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to register new user accounts with administrator privileges on affected WordPress sites, potentially leading to a complete compromise of the website.

  • Administrator access to the website.
  • Unauthenticated user registration.
  • Full website compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts WordPress sites using the King Addons plugin. The immediate first step is to identify all instances of this plugin, determine their exposure, and ascertain which team is accountable for the WordPress platform or specific site. Once ownership is confirmed, a risk-based remediation plan can be developed, potentially involving coordination with the plugin vendor if a fix is available or implementing compensating controls.

  • WordPress platform owners should address this.
  • Verify plugin reachability and site criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the King Addons for Elementor plugin?

King Addons for Elementor is a WordPress plugin that extends the Elementor page builder. It provides site administrators with additional widgets, templates, and functional elements, including tools for managing user registration and login forms on a website.

What does CVE-2025-8489 mean for my site security?

CVE-2025-8489 involves a weakness classified as Improper Privilege Management (CWE-269). This means the plugin fails to enforce proper checks during the user registration process, allowing someone to register an account with higher permissions than intended, such as an administrator.

How does an attacker trigger this vulnerability?

An attacker triggers this by interacting with the plugin's registration interface, which incorrectly permits the selection or assignment of administrative roles. Simply having the registration feature disabled or hidden does not necessarily mitigate the risk if the underlying code remains reachable and active on the server.

Is my website at risk from this vulnerability?

According to Halo Surface Signal, this vulnerability is considered highly relevant because the affected plugin is designed to provide public-facing registration features. If your site uses this plugin and allows user registration, the vulnerable interface is likely exposed to the internet by design.

What should I do if I use this plugin?

Identify all WordPress sites where King Addons is installed. Once you have a list, verify if you are running an affected version. Coordinate with your site administrators to determine if the registration features are necessary, and develop a plan to update or restrict the plugin until a secure version is confirmed.

References