More

    Another major WordPress add-on security flaw could affect 10,000 sites – find out if you’re affected



    • King Addons plugin had two critical flaws enabling full WordPress site takeover
    • Bugs allowed unauthenticated file uploads and privilege escalation via registration endpoint
    • Users must update to version 51.1.37 to patch both vulnerabilities

    King Addons for Elementor, a commercial WordPress plugin that extends the Elementor page builder with extra website builder widgets, templates, and design features, carried two critical-level vulnerabilities that allowed threat actors to fully take over vulnerable websites, experts have warned.

    In a new security advisory, Patchstack detailed two bugs: an unauthenticated arbitrary file upload flaw (CVE-2025-6327), and a privilege escalation via registration endpoint flaw (CVE-2025-6325). The former has a severity score of 10/10 (critical), while the latter 9.8/10 (also critical).


    https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img