CVE-2025-39596 is a weak authentication vulnerability in the Quentn WP WordPress plugin from Quentn.com GmbH. The issue affects Quentn WP through version 1.2.8. Based on the available description, the flaw allows privilege escalation due to insufficiently strong authentication controls. Specific vulnerable functions, code paths, and exploitation mechanics are not provided in the available content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (CVE-2025-39596.py) targeting the Quentn WP WordPress plugin (versions <= 1.2.8) for an unauthenticated privilege escalation vulnerability (CVE-2025-39596). The exploit works by sending a specially crafted POST request to the vulnerable API endpoint (/wp-json/quentn/api/v1/users) on the target WordPress site. The payload is a base64-encoded JSON object containing the new user's details and the desired role (default: administrator), along with a timestamp and a hash for validation. The script supports various options for evasion (custom headers, proxy, SSL bypass, cookies) and is designed for operational use, allowing attackers to create a new admin user without authentication. The repository includes a README with detailed usage instructions, a requirements.txt for dependencies (requests, urllib3), and a license restricting redistribution. The main entry point is CVE-2025-39596.py, which is modular and user-friendly, making it straightforward to use for penetration testing or red teaming against vulnerable WordPress installations.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.