Another Major WordPress Plugin Security Flaw May Affect 10,000 Sites – Find Out If You’re Affected


  • The King Addons plugin had two critical bugs that allowed the full takeover of the WordPress site
  • Bugs allowed unauthorized file uploads and privilege escalation via registry endpoint
  • Users should update to version 51.1.37 to fix both vulnerabilities

King Addons for Elementor, a commercial WordPress plugin that extends the Elementor page builder with additional website builder widgets, templates and design features, carried two critical-level vulnerabilities that allowed threat actors to fully take over vulnerable websites, experts have warned.

In a new security advisory, Patchstack described two flaws: an unauthorized arbitrary file upload flaw (CVE-2025-6327) and a privilege escalation via registry endpoint flaw (CVE-2025-6325). The former has a difficulty of 10/10 (critical), while the latter 9.8/10 (also critical).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top