Description
This module exploits an unauthenticated privilege escalation vulnerability in the WordPress King Addons for Elementor plugin (versions 24.12.92 to 51.1.14). The vulnerability exists in the handle_register_ajax() function which allows unauthenticated attackers to specify the user_role parameter during registration, enabling them to create administrator accounts.
This exploit requires a WordPress page containing the King Addons "Login Register Form" Elementor widget, which exposes the required nonce token in the page's JavaScript. The NONCE_PAGE option must be set to the path of such a page.
Once an administrator account is created, the module uploads and executes a malicious plugin to achieve remote code execution (RCE).
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/wp/king_addons_privilege_escalationmsf undefined(king_addons_privilege_escalation) > show actions ...actions...msf undefined(king_addons_privilege_escalation) > set ACTION < action-name >msf undefined(king_addons_privilege_escalation) > show options ...show and set options...msf undefined(king_addons_privilege_escalation) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub