WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
These articles are AI-generated summaries. Please check the original sources for full details.
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
A critical vulnerability in the WordPress King Addons plugin (CVE-2025-8489) is being actively exploited, allowing unauthenticated attackers to create admin accounts. With a CVSS score of 9.8, Wordfence has blocked over 48,400 exploit attempts since October 2025.
Why This Matters
The flaw stems from improper role restrictions during user registration, enabling privilege escalation without authentication. This exposes sites to full control takeover, malware injection, and traffic redirection. Attackers have already launched mass exploitation campaigns, targeting over 10,000 active plugin installations with 75 attempts blocked in the last 24 hours alone.
Key Insights
- “CVE-2025-8489 (CVSS 9.8)” – Wordfence, 2025
- “handle_register_ajax() function vulnerability” – WordPress plugin code
- “Patched in version 51.1.35” – Maintainers, September 2025
Practical Applications
- Use Case: WordPress administrators must update to 51.1.35+ and audit admin users
- Pitfall: Delayed updates leave sites exposed to credential theft and code injection
References:
Continue reading
Next article
How MoE Models Outperform Transformers in Inference Speed Despite More Parameters
Related Content
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
Attackers are actively exploiting critical FortiGate vulnerabilities (CVE-2025-59718 & CVE-2025-59719) with a CVSS score of 9.8, prompting urgent patching recommendations.
Microsoft Patches 63 Security Flaws, Including Critical Windows Kernel Zero-Day Under Active Attack
Microsoft patches 63 security flaws, including a critical Windows Kernel zero-day under active exploitation (CVE-2025-62215).
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution
A critical vm2 Node.js vulnerability (CVE-2026-22709, CVSS 9.8) allows sandbox escape via Promise handler bypass.