CVE-2025-2563 is an unauthenticated privilege-escalation vulnerability in the WordPress User Registration & Membership plugin before version 4.1.2. When the Membership Addon is enabled, the plugin does not properly prevent attacker-controlled account role assignment during registration, allowing a remote unauthenticated user to set the role of a newly created account. As described in the provided content, this flaw can be abused to register a user with administrator privileges. The issue is in the plugin’s registration and membership handling logic, specifically improper validation or enforcement of allowed roles during account creation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a standalone Python exploit and a README. The main file, `CVE-2025-2563.py`, is a multithreaded mass-exploitation script targeting CVE-2025-2563 in the WordPress User Registration & Membership plugin. It is not a framework module. The script normalizes target URLs, creates HTTP sessions with TLS verification disabled, rotates between a small pool of browser User-Agent strings, scrapes target pages for registration and membership metadata, extracts nonce values from embedded JavaScript (`ur_membership_frontend_localized_data`), and iterates through discovered `form_id`, `membership_id`, and nonce combinations to register a new user and escalate privileges. The README describes the intended chain clearly: fetch membership pages, extract identifiers/nonces, POST to `/wp-admin/admin-ajax.php` with `action=user_registration_user_form_submit`, abuse membership nonce handling to assign an administrator-level membership/role, then verify success by requesting `/wp-admin/users.php` and `/wp-admin/plugin-install.php`. Successful registrations are logged to `reg.txt`, and confirmed admin credentials are logged to `NATA_admin.txt`; the password is hardcoded as `NATA_adminSA`. The repository structure is minimal: one operational exploit script plus documentation. Overall, this is a real offensive exploit for unauthenticated web-based privilege escalation against vulnerable WordPress plugin deployments, with mass-target support and built-in credential logging.
Repository contains a single Python exploit script, a README, and a custom license. The main file, CVE-2025-2563.py, is a standalone mass-exploitation tool targeting CVE-2025-2563 in the WordPress User Registration & Membership plugin before 4.1.2. It is not tied to a common exploit framework. The script uses requests, regex parsing, and concurrent threading to process multiple targets from an input list. Its workflow is a full exploitation chain: normalize target URLs, fetch public membership/registration pages, extract candidate membership IDs, form IDs, security tokens, and JavaScript nonces, submit a registration request to /wp-admin/admin-ajax.php using the user_registration_user_form_submit action, then send a second AJAX request using user_registration_membership_register_member with crafted members_data containing role=administrator. After exploitation, it attempts to authenticate to /wp-login.php and verify elevated privileges by requesting wp-admin pages. Successful registrations and admin compromises are written to reg.txt and Nx_admin.txt respectively. The README confirms the intended attack chain and target conditions. Overall, this is an operational web/network exploit for unauthenticated administrator account creation on vulnerable WordPress sites, not merely a detector or documentation-only repository.
This repository contains a single Metasploit module targeting CVE-2025-2563, a privilege escalation vulnerability in the WordPress 'User Registration & Membership' plugin. The exploit works by registering a new user via the plugin's AJAX endpoint, escalating that user to administrator, logging in, and then uploading and executing a PHP payload (such as a Meterpreter shell) via a malicious plugin. The module is written in Ruby and leverages Metasploit's HTTP and WordPress libraries. The main endpoints targeted are the WordPress AJAX handler (/wp-admin/admin-ajax.php) for registration and privilege escalation, and the plugin upload directory for payload execution. The exploit is operational and provides remote code execution as the web server user on vulnerable WordPress installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation vulnerability in the WordPress User Registration plugin, referenced as a Metasploit module PR.
A similar privilege escalation vulnerability in the same WordPress plugin, referenced as an example of a better Nuclei template implementation (dynamic nonce/form/membership extraction and admin verification).
An unauthenticated privilege escalation vulnerability in the WordPress User Registration & Membership plugin, referenced in the context of adding an exploit module.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.