CVE-2025-10042 is an SQL injection vulnerability in the Quiz Maker plugin for WordPress affecting all versions up to and including 6.7.0.56. The flaw is caused by insufficient escaping of a user-controlled value derived from spoofable client IP headers and by failure to properly parameterize the resulting SQL query. In affected deployments, if the application is configured to trust a user-supplied header such as X-Forwarded-For for client IP determination, an unauthenticated attacker can supply crafted input in that header and cause additional SQL syntax to be appended to an existing query. The issue is specifically tied to configurations where IP-based user limiting is enabled and the server retrieves the client IP from a user-controlled field.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (52465.py) plus a README. The exploit targets CVE-2025-10042 in the WordPress Quiz Maker plugin (<= 6.7.0.56), abusing improper sanitization of an HTTP header (default X-Forwarded-For) to perform time-based blind SQL injection. Core capabilities: - Vulnerability check: sends a baseline request then an injected payload "1' OR SLEEP(3)#" and flags vulnerable if the response time is sufficiently delayed. - Data extraction: implements time-based inference with binary search to recover (a) LENGTH((query)) and (b) each character via ASCII(SUBSTRING(...)) comparisons, using 1-second sleeps. - Credential dumping: hardcoded queries against WordPress table wp_users for ID=1 to extract user_login, user_email, and user_pass (password hash). - Custom query mode: user can supply an arbitrary SQL query expected to return a single scalar value, which the script will extract. Operational details: - Network requests are made with Python requests.get() to a user-specified URL+path; TLS verification is disabled (verify=False) and urllib3 warnings are suppressed. - The script is CLI-driven via argparse with options: --check, --dump, --query, configurable header name, and timeout. Notable limitations/assumptions: - Assumes WordPress table prefix is "wp_" and that the admin user is ID=1. - Extraction is time-based and may be unreliable on high-latency targets; thresholds are hardcoded (e.g., 0.8s for 1s sleeps). - No post-exploitation payload (e.g., RCE) is included; it focuses on database data exfiltration.
Repository contains a single Python proof-of-concept exploit (exploit.py) plus README, LICENSE, and requirements.txt. Purpose: Exploit CVE-2025-10042, a time-based blind SQL injection in the WordPress Quiz Maker plugin (<= 6.7.0.56). The script injects SQL via an HTTP header (default X-Forwarded-For) sent to a user-specified quiz page path. Core capabilities: - Vulnerability check: compares baseline response time vs. an injected SLEEP(3) payload to determine if the target is likely vulnerable. - Data extraction: uses boolean inference with SLEEP(1) and binary search to determine (1) the length of a query result and (2) each character via ASCII(SUBSTRING(...)). - Credential dumping: runs fixed queries against wp_users for ID=1 to extract user_login, user_email, and user_pass (password hash). - Custom query mode: operator can supply an arbitrary SQL SELECT expression via --query and the script will extract its output. Operational notes: - All requests are unauthenticated GETs to {base_url}/{path} with TLS verification disabled (verify=False) and warnings suppressed. - Timing thresholds are simplistic (e.g., >=0.8s for SLEEP(1) inference), so results may be noisy on high-latency targets. Structure: - exploit.py: main entry point with argparse options (--check, --dump, --query; -u/-p/-H/-t). - requirements.txt: pins requests==2.34.0. - README.md: usage examples and high-level explanation. Overall, this is an operational PoC that can exfiltrate sensitive WordPress user data via time-based blind SQLi, not merely a detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.