CVE-2025-8489
✓ Confirmed 0-Day
Triaged: March 5, 2026
1 article
EPSS Score
Source: FIRST.org · 2026-05-24
49.26%
probability
This CVE has a 49.26% probability
of being exploited in the next 30 days.
0%
Top 97.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
TheHackerNews
Dec 03, 2025
Signal Intelligence
Confidence
85%
EPSS
49.26%
Mentions
1
Last Seen
Dec 03, 2025
CNA Information
Analyst Note
CVE-2025-8489 is a 2025 vulnerability (published 2025-10-31) with explicit reporting of active exploitation in the wild by TheHackerNews. The critical CVSS 9.8 privilege escalation flaw allowing unauthenticated admin registration is actively exploited, and the recent publication date combined with confirmed in-the-wild attacks strongly indicates zero-day exploitation preceding or coinciding with patch availability.
Threat Actors 2
Just Evil
apt_group
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
Triage Info
Decided atMar 05, 2026