CVE-2025-3776 affects the Verification SMS with TargetSMS plugin for WordPress in all versions up to and including 1.5. The vulnerability is in the 'targetvr_ajax_handler' function, which does not properly validate the type of function that may be invoked. As a result, an unauthenticated attacker can trigger execution of arbitrary callable PHP functions exposed in the application context. The available description characterizes this as limited remote code execution, with phpinfo() given as an example of a callable function that can be executed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (CVE-2025-3776.py) targeting a critical unauthenticated remote code execution (RCE) vulnerability (CVE-2025-3776) in the 'Verification SMS with TargetSMS' WordPress plugin, versions 1.5 and below. The vulnerability arises from the plugin's use of call_user_func() on user-controlled input without proper sanitization, allowing attackers to invoke any PHP function present in memory. The exploit works by first checking the plugin version via the readme.txt file, then sending a crafted POST request to /wp-admin/admin-ajax.php with the action 'targetvrHHndler' and a callback parameter set to a function name (typically 'evil'). For successful exploitation, the attacker must ensure a malicious function (such as evil()) is loaded into the WordPress environment, commonly by injecting it into the active theme's functions.php file. The evil() function, when called, executes arbitrary shell commands provided via the cmd parameter and returns the output. The repository includes a README with detailed exploitation steps, risk assessment, and mitigation advice. The structure is straightforward: the main exploit script, a requirements.txt for dependencies, a README.md with technical and usage details, and a license file.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.