CVE-2025-2512 is a vulnerability in the File Away plugin for WordPress, affecting all versions up to and including 3.9.9.0.1. The vulnerability exists due to a missing capability check and lack of file type validation in the upload() function, allowing unauthenticated attackers to upload arbitrary files to the server. This can be exploited to upload malicious files, such as web shells, leading to potential remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python exploit scripts targeting the WordPress File-Away plugin (<= 3.9.9.0.1) and a README describing a full unauthenticated RCE chain. Structure: - get_config.py: Exploits CVE-2025-2539 (unauthenticated arbitrary file read). It first GETs the target root page to extract the `fileaway_stats` nonce from JavaScript (`var fileaway_stats ... nonce`). It then POSTs to `/wp-admin/admin-ajax.php` with `action=fileaway-stats` to obtain an encrypted/obfuscated download URL for a requested file path. The script leverages the plugin’s weak encryption scheme as an oracle to recover the encryption key and decrypt the webroot, then downloads `wp-config.php` and saves it locally. - file_upload.py: Exploits CVE-2025-2512 (unauthenticated arbitrary file upload). It reads the downloaded wp-config.php to extract `NONCE_KEY` and `NONCE_SALT`, then re-implements WordPress nonce generation (time-windowed tick + HMAC-MD5) to compute `fileaway-nonce`, `fileaway-fileup-nonce`, and a location nonce (`fileaway-location-nonce-<base64(path)>`). It POSTs to `/wp-admin/admin-ajax.php` with `action=fileaway-manager&act=upload`, attempting to bypass filetype checks by naming a PHP file as `.\0php` while claiming an allowed extension (e.g., `jpeg`). The script reports the expected accessible URL under `wp-content/<filename>`. Capabilities: - Unauthenticated arbitrary file read (notably wp-config.php) via admin-ajax action `fileaway-stats`. - Key recovery/decryption logic to derive webroot and successfully retrieve sensitive files. - Unauthenticated arbitrary file upload via admin-ajax action `fileaway-manager` upload function, enabling attacker-supplied PHP execution when the uploaded file is web-accessible. No C2 infrastructure is embedded; all network interaction is with the target WordPress site’s HTTP endpoints. The payload is user-provided (e.g., a PHP command execution snippet), making this an operational exploit chain rather than a pure PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.