The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single standalone Python exploit script, CVE-2025-11740.py, despite the filename not matching the vulnerability identifier used in the code. The script claims to target CVE-2025-6254 affecting Doctreat Core <= 1.6.8 on WordPress and performs unauthenticated privilege escalation by creating administrator accounts. Structure and operation: the script first normalizes targets and auto-detects HTTP vs HTTPS by probing the site root. It then attempts to harvest a registration nonce from either the homepage (/) or /wp-login.php using several regex patterns matching ajax_nonce-style variables. If a nonce is found, it submits a POST request to /wp-admin/admin-ajax.php with action doctreat_process_registration and registration fields including user_type=administrator. Usernames and emails are generated per target, while the password is hardcoded as Password@1234!. Capabilities: it supports single-target mode (-u) and bulk mode from a file (-f), uses a ThreadPoolExecutor for concurrent exploitation, tracks progress, and saves successful compromises to success_admin.txt and failures to failed_targets.txt. The exploit is operational rather than a mere proof of concept because it includes full account-creation logic and bulk automation, but payload customization is limited. Notable findings: the exploit disables TLS certificate warnings and verification, making it tolerant of invalid HTTPS deployments. Success detection is simplistic, relying on the presence of the string 'success' in the response body. No post-exploitation shell or code execution payload is included; the primary outcome is unauthorized administrator account creation on vulnerable WordPress/Doctreat installations.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.