CVE-2025-4380 is a local file inclusion vulnerability in the Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress, affecting all versions up to and including 4.89. The flaw exists in handling of the bsa_template parameter within the bsa_preview_callback function. Insufficient validation of user-supplied input allows an unauthenticated attacker to cause the application to include arbitrary local files from the server filesystem. Where the included file contains executable PHP code, this can result in execution of that code in the context of the web application. The issue can also be leveraged to bypass access restrictions and expose sensitive local files depending on server configuration and available file paths.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
bsa_template parameter, especially path traversal or file path payloads. Harden the WordPress environment by disabling PHP execution in upload directories, minimizing writable web-accessible locations, enforcing least privilege on filesystem permissions, and monitoring for anomalous requests to preview-related endpoints and unexpected file inclusion behavior.Patch, then assume compromise.
bsa_template parameter to an allowlist of expected template names or fixed internal paths, and by preventing user-controlled input from reaching file inclusion functions. Additional hardening should ensure that uploaded content cannot be interpreted as PHP and that unnecessary writable locations do not contain executable code.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (cve_2025_4380.py) and a detailed README for CVE-2025-4380, a Local File Inclusion (LFI) vulnerability in the Ads Pro Plugin for WordPress (versions 4.89 and below). The exploit works by sending a POST request to the /wp-admin/admin-ajax.php endpoint with the action parameter set to bsa_preview_callback and the bsa_template parameter set to a user-supplied file path. This allows unauthenticated attackers to read arbitrary files from the server, such as /etc/passwd or wp-config.php. The script supports single or mass exploitation, output saving, proxy/TOR routing, and has a retry mechanism for reliability. The README provides usage instructions, parameter descriptions, and example commands. The main entry point is cve_2025_4380.py, which is a standalone Python script. No framework is used. The only fingerprintable endpoint is the vulnerable /wp-admin/admin-ajax.php path on WordPress sites with the affected plugin.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.