CVE-2025-2266 affects the Checkout Mestres do WP for WooCommerce WordPress plugin in versions 8.6.5 through 8.7.5. The plugin's cwmpUpdateOptions() function lacks a required capability check, allowing unauthorized modification of WordPress configuration data. As a result, an unauthenticated attacker can update arbitrary site options. In the described attack path, this can be used to change the default registration role to administrator and enable user registration, after which the attacker can register a new account and obtain administrative access to the vulnerable WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script (CVE-2025-2266.py) targeting the 'Checkout Mestres do WP for WooCommerce' WordPress plugin, specifically versions 8.6.5 and 8.7.5. The exploit leverages an unauthenticated arbitrary options update vulnerability in the plugin's 'cwmpUpdateOptions' AJAX action, allowing an attacker to enable user registration and set the default role to 'administrator'. The script then registers a new user (with attacker-supplied username and email), who is automatically granted admin privileges. The exploit checks the plugin version by reading the plugin's readme.txt, then performs the attack via POST requests to the WordPress AJAX and registration endpoints. The repository also includes a README.md with detailed usage instructions and a LICENSE file. The exploit is operational and provides full admin access to the attacker on vulnerable targets.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.