Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small Python-based WordPress exploitation toolkit with 3 files: a minimal README, exploiter.py as the main exploit, and check.py as a post-exploitation credential validator. The main script is multithreaded and designed to process a list of target WordPress sites. For each target, it requests /register, extracts a ct_register_nonce from the HTML, then submits a crafted POST to /wp-admin/admin-ajax.php using action=ct_add_new_member. The POST includes attacker-controlled registration fields and explicitly sets ct_user_role=administrator, aiming to create a new admin account. Successful results are written to success_results.txt, while raw server responses are stored under debug_responses/ for troubleshooting. Usernames are randomly generated with the prefix Nxploited and emails use a gmail.com domain; the password is hardcoded as xplpass. The companion check.py script reads credential lines from success_results.txt, logs into /wp-login.php, verifies dashboard access at /wp-admin/, and then requests /wp-admin/plugin-install.php to determine whether the account has administrator privileges. Confirmed admin accounts are saved to admin_accounts.txt. Overall, this is an operational exploit rather than a mere detector: it attempts account creation on remote web targets and includes a validation workflow for confirming privileged access.
Repository contains a single Nuclei template (CVE-2025-39459.yaml) plus a README. The template targets CVE-2025-39459 in the Real Estate 7 WordPress theme (<= 3.5.2), an unauthenticated privilege escalation/admin account creation issue caused by improper validation of the ct_user_role parameter in the ct_add_new_member AJAX action. Template flow: (1) GET /register to scrape ct_register_nonce from HTML using regex extractors; (2) POST /wp-admin/admin-ajax.php with form-encoded parameters including action=ct_add_new_member, randomized username/email, a fixed password ("RootHarpy"), and ct_user_role=administrator, reusing cookies from the first request. Success is determined by HTTP 200 plus JSON body indicators (e.g., "success":true/1 or "status":"success"). On success it extracts user_id and message fields from the JSON response. Overall purpose: automated exploitation/verification via Nuclei that can result in creation of a new administrator account on vulnerable WordPress sites, not merely passive detection.
Repository contains a single Python exploit tool (CVE-2025-39459.py) plus README and MIT LICENSE. The script is a multi-threaded network exploit targeting WordPress sites running the Real Estate 7 theme <= 3.5.2. Exploitation flow: (1) for each target base URL, it requests /register and regex-extracts a ct_register_nonce value; (2) it submits a POST to /wp-admin/admin-ajax.php with action=ct_add_new_member and user-supplied fields, critically setting ct_user_role=administrator; (3) on JSON response indicating success, it records the created credentials (random username/email with prefix Nxploited_####, fixed password xplpass) to success_results.txt. The tool also writes per-target raw responses to debug_responses/<sanitized_target>.resp.txt to aid troubleshooting when nonce extraction or JSON parsing fails. It disables TLS verification (verify=False) and suppresses urllib3 warnings, uses a queue + worker threads (default 10), and renders a Rich live dashboard showing progress and recent results. Overall purpose: automated scanning/exploitation at scale to create administrator accounts on vulnerable sites (unauthenticated privilege escalation).
Repository contains a Python exploit tool for CVE-2025-39459 targeting the Real Estate 7 WordPress theme (<= 3.5.2). Structure: (1) CVE-2025-39459.py is the main multi-threaded exploitation script with a Rich TUI dashboard; it loads targets from a user-specified list (default list.txt per README), normalizes missing schemes, and processes targets concurrently. For each target it performs a GET to /register to extract the ct_register_nonce from HTML, then POSTs to /wp-admin/admin-ajax.php with action=ct_add_new_member and a crafted form body that includes ct_user_role=administrator, thereby creating an admin user without authentication if the site is vulnerable. Successful hits are logged to success_results.txt with generated username/email (prefix Nxploited_####) and a fixed password (default xplpass). Debugging artifacts are written per-target into debug_responses/<sanitized_target>.resp.txt, including cases where the nonce is missing, JSON parsing fails, or exceptions occur. (2) README.md documents affected product/versions, high-level exploit flow, dependencies (requests/urllib3/rich), and usage. (3) LICENSE is a restrictive custom license. Overall purpose: automated scanning/exploitation to achieve unauthenticated administrator account creation on vulnerable WordPress sites via the theme’s AJAX registration handler.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.