CVE-2025-8489Critical· 9.8▾ AbyssalPoC availableThe King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 1.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.6%
Metasploit ×1 (last check)
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2025-67727Critical· 9.8Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js
CVE-2026-46434High· 7.1wger is a free, open-source workout and fitness manager
CVE-2026-105688Medium· 6.7Penpot is an open-source design and prototyping platform
CVE-2026-104955Medium· 5.4Plane is an open-source project management tool