CVE-2025-15403 is a privilege escalation vulnerability in the RegistrationMagic plugin for WordPress affecting all versions up to and including 6.0.7.1. The issue stems from the plugin's add_menu functionality being reachable through the rm_user_exists AJAX action, which permits arbitrary modification of the admin_order setting. By injecting an empty slug into the order parameter, an unauthenticated attacker can manipulate the plugin's menu-generation logic. When the WordPress admin menu is later rebuilt, the plugin assigns the manage_options capability to a targeted role. Exploitation is possible without authentication for the vulnerable AJAX interaction, but completing the privilege escalation path requires control of at least a subscriber-level account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python exploit project for CVE-2025-15403 affecting the RegistrationMagic WordPress plugin up to 6.0.7.1. It contains one main code file (CVE-2025-15403.py), a README with vulnerability explanation and usage context, and a custom license. The Python script is not part of a larger framework and appears to be the primary entry point. The exploit targets an unauthenticated privilege-escalation flaw in the plugin’s rm_user_exists AJAX handler, abusing the rm_options_admin_menu path and attacker-controlled order parameter to inject an empty slug. According to the included documentation and script flow, this causes the plugin to later grant manage_options to a chosen role such as Subscriber, resulting in effective administrator takeover. Capabilities exposed by the script include: bulk target processing with threading; a registration mode for creating WordPress users on targets; an exploit-only mode that sends the unauthenticated primitive; and a deeper verification mode that logs in with supplied credentials, checks /wp-admin and /wp-admin/plugin-install.php access, and uploads a verification plugin ZIP to confirm administrative control. The script writes multiple result files for primitive success, admin dashboard access, and plugin upload success. Notable target-facing endpoints and artifacts include the WordPress login and admin paths (/wp-login.php, /wp-admin, /wp-admin/plugin-install.php), the vulnerable AJAX action rm_user_exists, the RegistrationMagic slug rm_options_admin_menu, and exploit parameters such as enable_admin_order=yes and role keys like _Subscriber. Overall, this is an operational exploit automation tool for mass exploitation and post-escalation verification of a WordPress plugin privilege-escalation vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.