User Profile Builder (WordPress plugin) versions prior to 3.15.2 implement an improper password reset process that allows an unauthenticated attacker to reset the password of an arbitrary WordPress user account by issuing only a small number of crafted requests and knowing the target’s username (including administrator usernames). This results in account takeover of the targeted user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, single-script Python exploit project centered on CVE-2025-15030, targeting the WordPress User Profile Builder plugin before 3.15.2. The structure is simple: one main Python script (CVE-2025-15030.py), a README describing operation and attack chains, and a custom license. The script is interactive and intended for bulk processing of multiple WordPress targets using concurrent threads. The exploit is not a framework module; it is a standalone operational tool. Its primary capability is account takeover through password reset abuse. According to the code/comments and README, it implements two attack chains: (1) a native WordPress wp-login reset workflow and (2) a Profile Builder reset-from-link workflow using supplied reset URLs from pb_reset_links.txt. After resetting a password to a hardcoded value (Nxploited_adminSA), it enumerates likely usernames, attempts login, and performs strict administrator verification by checking multiple wp-admin pages for admin markers. If administrator access is confirmed, the script attempts post-exploitation by deploying a server-side payload using three methods: plugin ZIP upload through /wp-admin/update.php?action=upload-plugin, REST API upload through /wp-json/wp/v2/plugins, or direct file write through /wp-admin/plugin-editor.php. It then verifies shell availability at /wp-content/plugins/Nxploited/Nx.php and logs successful shell paths. This makes the repository more than a proof of concept: it includes credential takeover, privilege verification, and optional web shell deployment. Fingerprintable target endpoints are almost entirely WordPress-specific and include wp-login reset paths, wp-admin verification pages, the WordPress REST API users/plugins endpoints, author archive enumeration paths, and the final plugin shell path. Local artifacts include pb_reset_links.txt, scan_results/wp_login_reset_success.txt, scan_results/shells.txt, Nxploited.zip, and Nx.php. Overall, the repository’s purpose is automated exploitation of vulnerable or weakly protected WordPress password reset flows, followed by administrator takeover and persistence via plugin-based shell upload.
This repository is a small standalone Python mass-exploitation tool centered on wp.py, with supporting text files for targeting and reconnaissance. The README only names CVE-2025-15030. Dork.txt contains the plugin fingerprint path /wp-content/plugins/profile-builder/, suggesting the intended target is WordPress sites running the Profile Builder plugin. target.txt is a large bundled list of candidate WordPress sites and IP-based hosts for bulk scanning/exploitation. The main script, wp.py, is an interactive multithreaded Python program using requests, concurrent.futures, and colorama. Its workflow is: (1) normalize each target URL, (2) enumerate users through /wp-json/wp/v2/users, (3) select the lowest-ID account and use its slug as the username, (4) initiate a lost-password request at /wp-login.php?action=lostpassword while supplying a hardcoded reset key value ('hacked'), (5) visit /wp-login.php?action=rp&key=hacked&login={username}, and (6) submit a final password reset to /wp-login.php?action=resetpass with an operator-chosen password. If the response contains 'Your password has been reset', the script treats the target as compromised and appends the URL, username, and new password to vulnerable.txt. The exploit is not merely a detector: it attempts full account takeover by changing credentials. It is operational rather than a simple proof of concept because it includes automated targeting, concurrency, result logging, and a working exploitation flow, though the payload is basic and hardcoded. The repository structure and included target list indicate a purpose of mass scanning and bulk exploitation of vulnerable WordPress installations rather than focused research or defensive validation.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical privilege escalation vulnerability in User Profile Builder affecting versions prior to 3.15.2.
An authentication/account-takeover vulnerability in the User Profile Builder WordPress plugin (pre-3.15.2) where an improper password reset process allows unauthenticated attackers to reset arbitrary users' passwords (including administrators) if they know the username.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.