CVE-2025-32579 is an unrestricted file upload vulnerability in SoftClever Limited Sync Posts affecting versions through 1.0. According to the provided description, the flaw allows upload of a file with a dangerous type, specifically enabling an attacker to upload a web shell to the web server. This is consistent with improper validation or restriction of uploaded file types, allowing executable server-side content to be stored in a web-accessible or executable location.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2025-32579, targeting the Sync Posts WordPress plugin (<= 1.0) by SoftClever Limited. The exploit leverages an unrestricted file upload vulnerability, allowing authenticated attackers to upload arbitrary PHP files (such as web shells) to the server via the plugin's 'website_url' import feature. The main script, 'CVE-2025-32579.py', automates the attack: it logs into the target WordPress site using provided credentials, generates a malicious PHP API that returns a JSON post referencing the attacker's shell, and then instructs the vulnerable plugin to import from this API. The plugin fetches the shell and stores it in the 'wp-content/uploads' directory, enabling remote code execution. The repository includes a README with detailed usage instructions, a LICENSE, and a requirements.txt for dependencies. The exploit is operational, requiring only valid WordPress credentials and a reachable attacker-controlled server to host the fake API and shell.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.