Another major WordPress add-on security flaw could affect 10,000 sites – find out if you’re affected

https://www.profitableratecpm.com/f4ffsdxe?key=39b1ebce72f3758345b2155c98e6709c

  • The King Addons plugin presented two critical flaws allowing the complete takeover of the WordPress site
  • Bugs allowed unauthenticated file uploads and privilege escalation through the recording endpoint
  • Users should update to version 51.1.37 to fix both vulnerabilities

King Addons for Elementor, a commercial WordPress plugin that extends the Elementor page builder with additional widgets, templates and website design features, had two critical-level vulnerabilities that allowed malicious actors to take over vulnerable websites entirely, experts warned.

In a new security advisory, Patchstack detailed two bugs: an unauthenticated arbitrary file upload flaw (CVE-2025-6327) and privilege escalation via recording endpoint flaw (CVE-2025-6325). The former has a severity score of 10/10 (critical), while the latter 9.8/10 (also critical).

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button