CVE-2025-2011 is a generic SQL injection vulnerability in the Slider & Popup Builder by Depicter WordPress plugin affecting all versions up to and including 3.6.1. The flaw is caused by insufficient escaping of the user-controlled 's' parameter and insufficient preparation of the resulting SQL query. As a result, an unauthenticated attacker can append arbitrary SQL fragments to an existing query and manipulate backend database operations. The provided context specifically states that this issue can be used to extract sensitive information from the WordPress database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2025-2011.py) targeting a SQL injection vulnerability in the WordPress Depicter plugin (version 3.6.1). The exploit automates the process of extracting database schema and data from a vulnerable WordPress site by sending crafted GET requests to the /wp-admin/admin-ajax.php endpoint, abusing the 'depicter-lead-index' action. The script supports enumeration of databases, tables, and columns, and can extract table data, saving results as CSV files in a structured output directory. The code is operational and provides a practical means for attackers to exfiltrate sensitive data from affected WordPress installations. The repository also includes a brief README with usage instructions.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-2011, an unauthenticated SQL injection vulnerability in the Depicter Slider & Popup Builder WordPress plugin (versions up to and including 3.6.1). The repository contains two files: a Python exploit script (CVE-2025-2011.py) and a detailed README.md. The exploit script allows an attacker to target a single URL or a list of URLs, sending crafted SQL injection payloads to the /wp-admin/admin-ajax.php endpoint. If successful, the script extracts bcrypt password hashes from the WordPress database and saves them to a file, optionally attempting to crack them using Hashcat. The README provides comprehensive usage instructions, vulnerability details, mitigation advice, and references. The exploit is unauthenticated, requires no special privileges, and targets a network-accessible endpoint, making it a high-severity issue for affected WordPress sites.
This repository contains a Python proof-of-concept exploit for CVE-2025-2011, an unauthenticated SQL injection vulnerability in the Depicter WordPress plugin (versions 3.6.1 and below). The exploit script (CVE-2025-2011.py) allows an attacker to target a single URL or a list of URLs, sending crafted SQL injection payloads to the vulnerable 'admin-ajax.php' endpoint. If successful, the script extracts bcrypt password hashes from the WordPress user database and saves them locally. The user is optionally prompted to crack these hashes using Hashcat and a wordlist. The repository also includes a detailed README.md with vulnerability background, usage instructions, mitigation advice, and references. The exploit is unauthenticated, requires no special privileges, and targets a high-severity vulnerability with potential for significant data leakage. No framework is used; the code is standalone Python.
This repository contains a Python proof-of-concept exploit for CVE-2025-2011, a SQL injection vulnerability in the 'Slider & Popup Builder by Depicter' WordPress plugin (versions up to 3.6.1). The main file, CVE-2025-2011.py, allows the user to test single or multiple WordPress sites for the vulnerability by sending crafted SQL injection payloads to the /wp-admin/admin-ajax.php endpoint. If successful, the script extracts bcrypt password hashes from the wp_users table and saves them to a file. The user is optionally prompted to crack these hashes using Hashcat and the rockyou.txt wordlist. The script is interactive, supports colored output, and logs results per target. The README.md provides detailed usage instructions, requirements, and legal disclaimers. No framework is used; the exploit is standalone and focused on demonstrating the vulnerability and extracting sensitive data from affected WordPress installations.
This repository contains a single Metasploit auxiliary module targeting CVE-2025-2011, an unauthenticated SQL injection vulnerability in the Depicter Slider & Popup Builder WordPress plugin (versions <= 3.6.1). The exploit works by sending a crafted GET request to the /wp-admin/admin-ajax.php endpoint with the 'action' parameter set to 'depicter-lead-index' and the 's' parameter containing a SQL injection payload. The module leverages Metasploit's WordPress and SQLi libraries to automate the attack and extract user credentials from the database. The code is operational and can be used to verify and exploit the vulnerability on affected WordPress installations. The only file present is a Ruby script structured as a standard Metasploit module, with clear references to the CVE, vulnerability details, and exploitation logic.
This repository provides a proof-of-concept (PoC) environment and exploit for CVE-2025-2011, a SQL injection vulnerability in the Depicter Slider & Popup Builder WordPress plugin (versions < 3.6.2). The structure includes a Docker-based environment (docker-compose.yml) to deploy WordPress with the vulnerable plugin, a shell script (install-plugin.sh) to automate plugin installation, and a Python script (poc.py) that exploits the SQL injection vulnerability. The PoC script can check for vulnerability, extract admin credentials, or execute arbitrary SQL queries via a crafted request to /wp-admin/admin-ajax.php. The README.md provides detailed setup and usage instructions. The main attack vector is network-based, targeting the WordPress admin-ajax.php endpoint. The repository is a functional PoC, not weaponized, and is intended for testing and educational purposes.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in the WordPress Depicter plugin, referenced as a Metasploit module PR.
Unauthenticated SQL injection vulnerability in Slider & Popup Builder by Depicter (<= 3.6.1).
An unauthenticated SQL injection vulnerability in the WordPress Depicter ("Slider & Popup Builder") plugin affecting versions <= 3.6.1, for which a Metasploit auxiliary module was added.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.