CVE-2025-32641 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Anant Addons for Elementor WordPress plugin by anantaddons in versions through 1.1.5. The available information indicates the plugin lacks adequate anti-CSRF protections on one or more state-changing actions, allowing forged requests to be submitted in the context of an authenticated victim’s session. Specific vulnerable functions or endpoints are not identified in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (POC) exploit for CVE-2025-32641, a critical CSRF vulnerability in the Anant Addons for Elementor WordPress plugin (versions <= 1.1.5). The exploit is delivered as an HTML form that, when visited by a logged-in WordPress administrator, silently submits a POST request to the vulnerable admin-ajax.php endpoint, causing the installation and activation of an arbitrary plugin from the WordPress repository. The repository contains only a LICENSE file and a README.md, with the latter including a detailed description of the vulnerability, its impact, and the exploit code. No actual code files or scripts are present beyond the HTML POC. The exploit requires no authentication and leverages the lack of CSRF protection in the plugin's AJAX handler. The main fingerprintable endpoint is the admin-ajax.php URL with the 'install_act_plugin' action parameter.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.