CVE-2025-3102 affects the SureTriggers: All-in-One Automation Platform plugin for WordPress. In all versions up to and including 1.0.78, the plugin's authentication logic in the 'autheticate_user' function fails to properly validate an empty 'secret_key' value. Because of this missing empty-value check, an unauthenticated attacker can bypass authentication when the plugin is installed and activated but has not been configured with an API key. Successful exploitation allows the attacker to create a new administrator account on the target WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a Python-based mass scanner + exploit for CVE-2025-3102 (SureTriggers WordPress plugin authentication/authorization bypass). Structure: - README.md: usage examples for scanner and exploit; states goal is mass scan/exploit and auto-create an Administrator role. - scann-verison.py: multi-threaded version scanner. It normalizes targets, tries HTTPS then HTTP, and requests common plugin files under /wp-content/plugins/(suretriggers|sure-triggers)/ to extract the plugin version using regex patterns (e.g., “Stable tag”, “Version”, constants). It classifies targets as vulnerable based on the stated target version (≤ 1.0.78) and writes vulnerable URLs to vuln.txt. - exploit-mass.py: multi-threaded mass exploitation tool. It validates target reachability (tries protocol and www variations, rotates User-Agent, uses HEAD/GET, disables TLS verification), then attempts exploitation against each target to create a new WordPress user with attacker-supplied username/email/password and assigns a role (administrator by default). It supports single-target (-u) and list mode (-l), configurable threads/timeouts, debug output, and optional post-exploit login verification; on success it prints credentials and the /wp-admin/ URL. Overall purpose: automate discovery of SureTriggers installations and exploit the auth bypass to gain administrative access by creating a new admin user at scale.
This repository contains a Python exploit (ex.py) targeting CVE-2025-3102, a critical authentication bypass in the SureTriggers WordPress plugin (versions up to and including 1.0.78). The exploit reads a list of target URLs from list.txt, checks the plugin version by fetching /wp-content/plugins/suretriggers/readme.txt, and attempts to exploit the vulnerability by sending a crafted JSON payload to the unauthenticated API endpoint /wp-json/sure-triggers/v1/automation/action. If successful, it creates a new WordPress user with attacker-controlled credentials (baribut:baribut). The repository structure is simple: ex.py (main exploit script), README.md (brief description), and list.txt (target list template). The exploit is operational and automates both detection and exploitation of the vulnerability.
This repository contains a Python exploit script (CVE-2025-3102.py) targeting an authorization bypass vulnerability in the SureTriggers WordPress plugin (versions <= 1.0.78). The exploit allows an unauthenticated attacker to create arbitrary WordPress user accounts by sending a specially crafted POST request to the '/wp-json/sure-triggers/v1/automation/action' REST API endpoint. The script first attempts to verify the plugin version by fetching '/wp-content/plugins/suretriggers/readme.txt', then constructs and sends a JSON payload to the vulnerable endpoint. The exploit is fully operational, providing customizable email, username, and password for the new user via command-line arguments. The repository includes a README with detailed usage instructions, a requirements.txt for dependencies (requests, colorama), and standard project files. The main exploit logic resides in 'CVE-2025-3102.py', which is the only code file. The attack vector is remote and network-based, requiring only HTTP access to the target WordPress site.
This repository contains a single Metasploit module (Ruby file) that exploits two authentication bypass vulnerabilities (CVE-2025-3102 and CVE-2025-27007) in the SureTriggers (aka OttoKit) WordPress plugin. The module allows an unauthenticated attacker to create a new WordPress administrator account by abusing the plugin's REST API endpoints. For CVE-2025-27007, it first resets the access key using a vulnerable endpoint, then proceeds to create the admin user. After gaining admin access, the module uploads a malicious plugin containing a PHP payload (such as a Meterpreter shell) and executes it, granting remote code execution on the target server. The exploit is highly weaponized, supporting multiple payload types and platforms (PHP, Unix, Windows). The main attack vector is network-based, targeting HTTP endpoints exposed by the vulnerable WordPress plugin. The code is structured as a standard Metasploit module, with clear separation of functions for checking vulnerability, exploiting, and cleaning up artifacts.
This repository contains a single Nuclei YAML template exploiting CVE-2025-3102, an authorization bypass vulnerability in the SureTriggers WordPress plugin (versions <= 1.0.78). The exploit sends a crafted POST request to the /wp-json/sure-triggers/v1/automation/action REST API endpoint, with a JSON payload that instructs the plugin to create a new WordPress user with attacker-controlled credentials. The template checks for a successful response by matching specific keywords and regexes in the response body. The exploit is operational and can be used to gain unauthorized access to affected WordPress sites. The repository is structured as a single YAML file compatible with the Nuclei scanning framework.
This repository contains a Python exploit script (run3.py) and a README.md for CVE-2025-3102, a vulnerability in the SureTriggers WordPress plugin (versions <= 1.0.78). The exploit automates detection of the vulnerable plugin version, validates the presence of a standard WordPress login page, and attempts to exploit the REST API endpoint '/wp-json/sure-triggers/v1/automation/action' to create a new admin user with attacker-supplied credentials. The script supports multi-threaded operation and randomizes the User-Agent header for each request. Successful exploits are logged to 'vulnerable.txt' in the format 'http://target.com/wp-login.php | username:password'. The repository is structured with a single exploit script and a detailed README explaining usage, options, and output. The main attack vector is network-based, targeting publicly accessible WordPress sites with the vulnerable plugin and REST API enabled.
This repository contains a Python exploit script (CVE-2025-3102.py) targeting CVE-2025-3102, a critical authentication bypass vulnerability in the SureTriggers WordPress plugin (versions <= 1.0.78). The exploit works by sending a specially crafted POST request to the vulnerable REST API endpoint '/wp-json/sure-triggers/v1/automation/action' with an empty 'st_authorization' header, allowing unauthenticated creation of administrator accounts. The script can automatically detect the plugin version by fetching '/wp-content/plugins/suretriggers/readme.txt' and provides a CLI for specifying the target URL and new user credentials. The repository also includes a README.md with detailed usage instructions and a LICENCE file. The exploit is operational and provides attackers with full admin access to vulnerable WordPress sites.
This repository provides a fully operational exploit for CVE-2025-3102, a critical vulnerability in the SureTriggers WordPress plugin (<= 1.0.78) that allows unauthenticated creation of administrator users via a vulnerable API endpoint. The main exploit script (Vanda-CVE-2025-3102.py) features a graphical user interface and automates the following steps: (1) scanning target URLs for vulnerability, (2) exploiting the flaw to create a new admin user (vanda_admin / Vanda@123), (3) uploading a PHP webshell (vanda_shell.php) for persistent remote access, and (4) attempting brute-force logins using the known credentials. The webshell is a feature-rich PHP backdoor supporting file management, command execution, and reverse/bind shell capabilities. The repository also includes a sample URL list (urls.txt) and documentation (README.md). All network interactions target standard WordPress endpoints, making this exploit highly effective against unpatched and misconfigured SureTriggers installations.
This repository contains a Python exploit script (CVE-2025-3102.py) targeting CVE-2025-3102, an authentication bypass vulnerability in the SureTriggers WordPress plugin (versions <= 1.0.78). The exploit leverages a missing check for an empty 'st_authorization' header in the plugin's REST API, allowing unauthenticated attackers to create new administrator accounts if the plugin is installed, activated, but not configured with an API key. The script first attempts to verify the plugin version by fetching the 'readme.txt' file from the target, then sends a crafted JSON payload to the '/wp-json/sure-triggers/v1/automation/action' endpoint with an empty 'st_authorization' header, resulting in the creation of a new admin user. The repository includes a README with detailed usage instructions and a LICENSE file. The main exploit file is standalone, written in Python, and provides operational exploitation capabilities.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in the WordPress SureTriggers plugin enabling admin creation and remote code execution, referenced as a Metasploit module PR.
An OttoKit/SureTriggers WordPress plugin authorization bypass that allows attacker-driven admin account creation; actively exploited shortly after disclosure.
Authentication bypass vulnerability in SureTriggers (All-in-One Automation Platform <= 1.0.78).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.