CVE-2025-2539 affects the WordPress File Away plugin in all versions up to and including 3.9.9.0.1. The flaw is caused by a missing capability check in the plugin's ajax() function, allowing unauthenticated attackers to invoke the vulnerable AJAX functionality without proper authorization. The exposed functionality relies on a reversible weak encoding algorithm, which can be leveraged to access and read arbitrary files from the underlying server. As a result, an attacker can retrieve sensitive local files such as application configuration files, stored credentials, and other confidential server-side data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python exploit scripts targeting the WordPress File-Away plugin (<= 3.9.9.0.1) and a README describing a full unauthenticated RCE chain. Structure: - get_config.py: Exploits CVE-2025-2539 (unauthenticated arbitrary file read). It first GETs the target root page to extract the `fileaway_stats` nonce from JavaScript (`var fileaway_stats ... nonce`). It then POSTs to `/wp-admin/admin-ajax.php` with `action=fileaway-stats` to obtain an encrypted/obfuscated download URL for a requested file path. The script leverages the plugin’s weak encryption scheme as an oracle to recover the encryption key and decrypt the webroot, then downloads `wp-config.php` and saves it locally. - file_upload.py: Exploits CVE-2025-2512 (unauthenticated arbitrary file upload). It reads the downloaded wp-config.php to extract `NONCE_KEY` and `NONCE_SALT`, then re-implements WordPress nonce generation (time-windowed tick + HMAC-MD5) to compute `fileaway-nonce`, `fileaway-fileup-nonce`, and a location nonce (`fileaway-location-nonce-<base64(path)>`). It POSTs to `/wp-admin/admin-ajax.php` with `action=fileaway-manager&act=upload`, attempting to bypass filetype checks by naming a PHP file as `.\0php` while claiming an allowed extension (e.g., `jpeg`). The script reports the expected accessible URL under `wp-content/<filename>`. Capabilities: - Unauthenticated arbitrary file read (notably wp-config.php) via admin-ajax action `fileaway-stats`. - Key recovery/decryption logic to derive webroot and successfully retrieve sensitive files. - Unauthenticated arbitrary file upload via admin-ajax action `fileaway-manager` upload function, enabling attacker-supplied PHP execution when the uploaded file is web-accessible. No C2 infrastructure is embedded; all network interaction is with the target WordPress site’s HTTP endpoints. The payload is user-provided (e.g., a PHP command execution snippet), making this an operational exploit chain rather than a pure PoC.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-2539, a vulnerability in the File Away WordPress plugin (versions <= 3.9.9.0.1) that allows authenticated arbitrary file read via a directory traversal flaw in the 'fileaway-stats' AJAX action. The main exploit code is in 'cve_wp.py', which is obfuscated but, according to the documentation and PoC logic, sends a crafted POST request to the '/wp-admin/admin-ajax.php' endpoint with the vulnerable parameters. The exploit requires a valid nonce (authenticated user context) and can be used to read sensitive files such as 'wp-config.php', leading to further compromise (e.g., database credentials, privilege escalation). The repository also includes a detailed 'readme.md' with technical analysis, attack flow, mitigation, and detection guidance. The structure is simple: one Python exploit file, a GitHub Actions workflow, and comprehensive documentation. No fake or destructive code is present; the exploit is a functional PoC for research and testing.
This repository contains a Python proof-of-concept exploit for CVE-2025-2539, targeting the File Away WordPress plugin (versions <= 3.9.9.0.1). The exploit leverages a missing capability check in the plugin's AJAX handler, allowing unauthenticated attackers to read arbitrary files from the server. The main script, 'CVE_2025-2539.py', takes a target URL and a filename as arguments, extracts a required nonce from the target's HTML, and sends a crafted POST request to the '/wp-admin/admin-ajax.php' endpoint. If successful, it retrieves a URL to the requested file and downloads its contents, saving it locally. The repository also includes a README.md with usage instructions and background information. No detection or fake code is present; the exploit is functional and demonstrates the vulnerability.
This repository contains a Python exploit script (mass_cve_2539.py) targeting CVE-2025-2539, an unauthenticated arbitrary file read vulnerability in the WordPress File Away plugin (<= 3.9.9.0.1). The script automates exploitation against multiple targets listed in a 'list.txt' file. For each target, it fetches a required nonce, exploits the vulnerable AJAX endpoint to read 'wp-config.php', extracts database credentials, checks for accessible phpMyAdmin interfaces, and attempts to connect to the MySQL database remotely. Results are saved in output files for further use. The exploit is operational, automates credential extraction and validation, and is intended for penetration testing or research on authorized systems only.
This repository contains a Python proof-of-concept exploit for CVE-2025-2539, targeting the WordPress File Away plugin (versions <= 3.9.9.0.1). The exploit leverages an unauthenticated arbitrary file read vulnerability via the /wp-admin/admin-ajax.php endpoint, specifically abusing the 'fileaway-stats' AJAX action. The script first fetches a required nonce from the target's web page, then sends a crafted POST request to retrieve the contents of a specified file (such as wp-config.php) from the server. The repository consists of the main exploit script (CVE-2025-2539.py) and a README.md with usage instructions and vulnerability details. The exploit is a standalone Python script, requires the 'requests' library, and is intended for educational and authorized penetration testing purposes only.
This repository provides a proof-of-concept (POC) exploit for CVE-2025-2539, a vulnerability in the File Away WordPress plugin (versions <= 3.9.9.0.1) that allows unauthenticated arbitrary file read due to missing authorization checks. The repository contains two files: a detailed README.md explaining the vulnerability, usage instructions, and reconnaissance tips (including a Fofa dork for finding targets), and a Bash script (cve-2025-2539.sh) that automates the exploitation process. The script works by extracting a required nonce from the target's main page, sending a POST request to the /wp-admin/admin-ajax.php endpoint to trigger the vulnerable action, and then downloading the contents of an arbitrary file specified by the user. The exploit is network-based and targets publicly accessible WordPress sites running the vulnerable plugin. No fake or destructive code is present; the script is a functional POC for file read exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.