Another major WordPress add-on security flaw could affect 10,000 sites – find out if you’re affected


  • King Addons plugin had two critical flaws enabling full WordPress site takeover
  • Bugs allowed unauthenticated file uploads and privilege escalation via registration endpoint
  • Users must update to version 51.1.37 to patch both vulnerabilities

King Addons for Elementor, a commercial WordPress plugin that extends the Elementor page builder with extra website builder widgets, templates, and design features, carried two critical-level vulnerabilities that allowed threat actors to fully take over vulnerable websites, experts have warned.

In a new security advisory, Patchstack detailed two bugs: an unauthenticated arbitrary file upload flaw (CVE-2025-6327), and a privilege escalation via registration endpoint flaw (CVE-2025-6325). The former has a severity score of 10/10 (critical), while the latter 9.8/10 (also critical).


Share this post:

Leave a Reply

Your email address will not be published. Required fields are marked *

From the latest gadgets to expert reviews and unbeatable deals — dive into our handpicked content across all things tech.