CVE-2025-34077 is an authentication bypass vulnerability in the WordPress Pie Register plugin affecting versions up to and including 3.7.1.4. The flaw allows an unauthenticated attacker to impersonate arbitrary WordPress users by sending a crafted POST request to the plugin's login endpoint. Exploitation involves setting the parameter social_site=true and manipulating the user_id_social_site parameter so that the application generates a valid WordPress session cookie for an attacker-chosen user ID, including administrative accounts. Because the vulnerable logic accepts attacker-controlled identity information without proper authentication validation, the attacker can obtain an authenticated session as another user. In environments where an impersonated administrator can access plugin upload functionality, this can be chained to upload a malicious plugin containing arbitrary PHP code, leading to remote code execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a working exploit for CVE-2025-34077, a critical authentication bypass vulnerability in the Pie Register WordPress plugin (versions <= 3.7.1.4). The main exploit is implemented in 'CVE-2025-34077.py', a Python script that sends a crafted POST request to the WordPress login endpoint. By manipulating the 'user_id_social_site' and 'social_site' parameters, the script is able to hijack an admin session and extract valid admin cookies without authentication. The exploit confirms success by displaying the hijacked cookies, which can then be used to access the WordPress admin dashboard as an administrator. The repository also includes a Nuclei YAML template ('CVE-2025-34077.yaml') for automated detection and exploitation. The README provides detailed usage instructions, technical background, and legal disclaimers. No fake or detection-only scripts are present; the code is a functional exploit. The attack vector is network-based, targeting the HTTP(S) interface of vulnerable WordPress sites.
This repository contains a working proof-of-concept exploit for CVE-2025-34077, targeting the WordPress Pie Register plugin (versions <= 3.7.1.4). The exploit is implemented in Python (pie.py) and leverages an unauthenticated POST request to the root URL of a vulnerable WordPress site. By sending a specific payload with the parameter 'user_id_social_site=1', the script tricks the plugin into authenticating the attacker as the admin user (user_id=1), resulting in the server issuing valid admin session cookies. The script prints these cookies, which can then be used to impersonate the admin in a browser or with tools like curl or Burp Suite. The repository consists of a detailed README.md explaining the vulnerability, affected software, and usage instructions, and a single exploit script (pie.py) that automates the attack. No detection or fake code is present; the exploit is functional and directly targets the vulnerability.
This repository contains a single Metasploit module targeting an authentication bypass and remote code execution (RCE) vulnerability in the WordPress Pie Register plugin (versions <= 3.7.1.4, CVE-2025-34077). The exploit works by sending a crafted POST request to the WordPress site to bypass authentication and obtain a valid session cookie (ideally for an admin user). Using this session, it generates a malicious WordPress plugin containing a PHP payload, compresses it as a ZIP archive, and uploads it to the target server. The payload is then executed by accessing its URL, resulting in arbitrary code execution on the server. The module is written in Ruby and is structured as a standard Metasploit exploit, leveraging Metasploit's HTTP and WordPress helper modules. The only file present is the exploit module itself, and it is fully operational, requiring only the target URL and a user ID to attempt exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.