The first step is simple:
Update King Addons for Elementor to the latest version now.If you cannot update right away, the next best response is containment:
- Deactivate the plugin
- Disable public registration if your site does not truly need it
- Remove or restrict public pages using the Login/Register widget
- Review all administrator accounts for unfamiliar users
- Inspect the site for signs of post-compromise activity
If you discover an unauthorized administrator account, do not treat that as a minor cleanup issue. Treat the site as potentially compromised. Review plugins, themes, recent file changes, unexpected redirects, and any suspicious content additions. WordPress’s own guidance on hacked sites recommends documenting the incident, changing passwords, rotating secrets, and checking for unauthorized users and file modifications.