Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24659, a time-based blind SQL injection vulnerability in the 'Premium Packages – Sell Digital Products Securely' WordPress plugin (wpdm-premium-packages) version 5.9.6 and below. The vulnerability exists in the 'orderby' parameter of the order list dashboard, which is not properly sanitized before being used in SQL queries. The exploit requires administrator credentials and automates the process of logging in and sending crafted SQL injection payloads to the vulnerable endpoint (/wp-admin/edit.php) to extract the database name by measuring response times. The repository consists of a detailed README.md explaining the vulnerability, exploitation steps, and root cause, and a single Python script (poc.py) that implements the attack. The code uses the 'requests' library to interact with the WordPress backend and demonstrates how to extract information from the database using time-based inference. No hardcoded malicious payloads or post-exploitation actions are present; the exploit is strictly a PoC for demonstrating the vulnerability.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.