Listen to this Post

The digital landscape is facing a new wave of threats as attackers exploit recently discovered critical vulnerabilities in popular WordPress plugins. These security flaws allow unauthorized users to gain administrative control and execute malicious code, putting websites, their owners, and visitors at significant risk. With WordPress powering millions of websites worldwide, even a single exploited vulnerability can ripple into large-scale cyberattacks.
Privilege Escalation in King Addons for Elementor
A severe privilege escalation vulnerability, tracked as CVE-2025–8489, has been identified in the King Addons plugin for Elementor, a widely used page builder for WordPress. This flaw allows attackers to gain administrative permissions during the registration process by specifying their user role without any restrictions. The vulnerability was discovered by security researcher Peter Thaleikis and became publicly known on October 30, 2025.
Almost immediately, attackers began targeting affected websites, with Wordfence, a prominent WordPress security company, blocking more than 48,400 exploit attempts. Analysis of attack patterns revealed a peak in activity between November 9 and 10, with two IP addresses responsible for the majority of attempts: 45.61.157.120 (28,900 attempts) and 2602:fa59:3:424::1 (16,900 attempts).
King Addons is installed on roughly 10,000 WordPress sites, offering additional widgets, templates, and features. The exploit involves sending a crafted admin-ajax.php request with user_role=administrator, effectively allowing attackers to create rogue admin accounts on compromised sites. Website administrators are urged to upgrade immediately to version 51.1.35, which addresses this critical vulnerability.
Remote Code Execution in Advanced Custom Fields: Extended
In parallel, Wordfence researchers have warned of another critical vulnerability in Advanced Custom Fields: Extended, affecting over 100,000 WordPress sites. Known as CVE-2025-13486, this flaw allows unauthenticated attackers to execute arbitrary code remotely.
The vulnerability affects plugin versions 0.9.0.5 through 0.9.1.1 and arises from a function that improperly handles user input before passing it to call_user_func_array(). Exploiting this flaw, attackers can inject backdoors, create administrative accounts, or take full control of the server. The vulnerability was responsibly disclosed by Marcin Dudek, head of Poland’s CERT, on November 18, and was patched by the plugin vendor in version 0.9.2 the very next day.
Administrators are strongly advised to update immediately or disable the plugin to prevent exploitation. Public disclosure of technical details means that attacks could escalate rapidly if patches are not applied.
What Undercode Say: Understanding the Risks and Implications
The discovery and exploitation of these vulnerabilities highlight a recurring problem in the WordPress ecosystem: third-party plugin security. While WordPress itself maintains robust core protections, plugins, especially popular ones like King Addons and Advanced Custom Fields: Extended, introduce significant attack surfaces.
From a security strategy perspective, these vulnerabilities underscore the importance of proactive plugin management. Website owners often underestimate the risks of outdated or vulnerable plugins, focusing primarily on themes or the core platform. This oversight is costly, as evidenced by the rapid targeting of King Addons immediately after public disclosure. Attackers exploit the window between disclosure and patch adoption, which can span hours or days, to create administrative backdoors, steal data, or compromise entire websites.
The technical mechanisms behind these exploits also illustrate evolving attack sophistication. Privilege escalation through user registration manipulation is a classic yet devastating flaw. Coupled with remote code execution vulnerabilities, which bypass authentication entirely, attackers gain near-complete control over compromised sites.
Additionally, the concentration of exploit attempts from a small number of IP addresses suggests organized campaigns rather than opportunistic attacks. Security teams must actively monitor logs for suspicious activity and newly created administrative accounts. Automated scanners like Wordfence play a crucial role but cannot substitute for timely patch management and auditing.
This situation also reflects on broader cybersecurity governance. Organizations relying heavily on WordPress should implement layered defenses, including strict plugin policies, access controls, and continuous monitoring. Cyber resilience is no longer a reactive measure; it must be baked into operations, with frequent updates and rapid incident response capabilities.
Furthermore, these vulnerabilities highlight the potential ripple effects of security flaws in widely adopted platforms. Compromised websites can serve as vectors for phishing, malware distribution, or even broader attacks on connected networks. The responsibility lies not just with plugin developers but also with website operators, hosting providers, and cybersecurity vendors to maintain vigilance and respond swiftly to threats.
🔍 Fact Checker Results
✅ CVE-2025–8489 affects King Addons for Elementor, allowing privilege escalation during user registration.
✅ CVE-2025-13486 affects Advanced Custom Fields: Extended, enabling unauthenticated remote code execution.
❌ Exploit attempts have been actively blocked by Wordfence, preventing widespread damage so far.
📊 Prediction
Cybercriminals will likely continue targeting outdated or unpatched WordPress plugins, with automation increasing attack volumes. 🌐
Websites failing to apply updates quickly may see unauthorized admin accounts or server-level compromises. ⚠️
Proactive patching, monitoring, and threat intelligence sharing will remain the most effective defense against these evolving vulnerabilities. 🔒
If you want, I can also create a more engaging, SEO-optimized version with even punchier subheadings and hooks to maximize clicks and readability. Do you want me to do that next?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




