Nks Email Subscription Popup through version 1.2.23 contains an SQL injection vulnerability caused by improper neutralization of special elements used in SQL commands. The flaw allows blind SQL injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24587, a SQL injection vulnerability in the 'Email Subscription Popup' WordPress plugin (versions <= 1.2.23). The exploit consists of a Python script (poc.py) and a detailed README.md. The PoC script automates the process of subscribing to the newsletter with both benign and a specially crafted malicious email address. The malicious email address is designed to exploit a SQL injection vulnerability that is triggered when an administrator attempts to delete the subscriber from the admin panel. The result is the deletion of all email subscriptions from the database. The repository is structured simply, with the main exploit logic contained in poc.py, which interacts with the WordPress site's AJAX endpoint. The README provides comprehensive details, including vulnerability explanation, reproduction steps, and remediation advice. No framework is used; this is a standalone PoC exploit.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.