CVE-2025-39401 is an unrestricted file upload vulnerability in mojoomla WPAMS affecting versions through 44.0 (17-08-2023). According to the provided content, the flaw allows upload of a file with a dangerous type, specifically enabling an attacker to upload a web shell to the web server. Based on the available information, the issue is consistent with insufficient validation or restriction of uploaded file types in the application's file upload functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains one standalone Python exploit script, CVE-2025-39401.py, targeting a presumed arbitrary-file-upload flaw in the WordPress Apartment Management plugin. It sends a multipart POST request to a target-relative member-registration page, registering a synthetic user and supplying an external PHP file as the amgt_user_avatar field. It disables TLS certificate validation, uses a desktop-browser User-Agent, and does not validate the initial upload response. After a five-second delay, it derives likely server-side filenames from the local shell name and upload-time Unix timestamp, then repeatedly requests candidate files in wp-content/uploads/apartment_assets/. A candidate is considered successful only when it returns HTTP 200 and contains the hard-coded Nxploited HTML marker. The script supports one URL via --url or interactive bulk processing from a file with configurable threads. It logs confirmed shell URLs locally. This is a functional exploitation workflow, but is classified as POC because the required shell.php payload is absent from the repository; successful RCE depends on an operator-provided PHP shell and target-side PHP execution in the upload directory.
This repository contains a single Python exploit script (CVE-2025-39401.py) targeting the WordPress WPAMS plugin (versions <= 44.0) for an arbitrary file upload vulnerability (CVE-2025-39401). The exploit automates mass exploitation by reading a list of target WordPress sites, uploading a user-supplied PHP shell (shell.php) via the vulnerable member registration endpoint, and brute-forcing the timestamp-based filename to locate the uploaded shell. The script uses multithreading for speed and logs successful shell URLs. The README provides detailed usage instructions, requirements, and a technical explanation of the vulnerability and exploitation process. No detection or fake code is present; this is a fully operational exploit. The main attack vector is network-based, exploiting a web application endpoint. The repository is structured with the main exploit script, a README, a license, and a requirements file.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.