CVE-2025-14124 is an SQL injection vulnerability in the Team WordPress plugin prior to version 5.0.11. The plugin does not properly sanitize and escape a parameter before incorporating it into a SQL statement through an AJAX action accessible to unauthenticated users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Go-based exploit for CVE-2025-14124, a time-based blind SQL injection vulnerability in the WordPress Team Plugin (versions < 5.0.11). The exploit is fully operational and automates the process of detecting the vulnerability, extracting sensitive database information, and optionally hijacking or creating a WordPress admin account if the target supports stacked queries. The main exploit logic is in 'main.go', which provides command-line options for targeting, extraction, and exploitation. The tool interacts with the vulnerable AJAX endpoint '/wp-admin/admin-ajax.php' by sending crafted POST requests with a malicious 'search' parameter. It can auto-discover the team page, extract required nonces and IDs, and perform both verification and exploitation. The README.md provides detailed usage instructions, prerequisites, and remediation advice. No framework is used; the exploit is standalone. The only code file is 'main.go', with the rest being documentation and ignore files.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in the Team WordPress Plugin. The content indicates the issue was verified through tested exploitation.
A high-severity unauthenticated SQL injection vulnerability in the Team WordPress plugin before version 5.0.11, allowing remote attackers to execute arbitrary SQL queries via a network-accessible AJAX action.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.