CVE-2025-4396 is a time-based SQL injection vulnerability in the Relevanssi – A Better Search plugin for WordPress. It affects all Free versions up to and including 4.24.4 and all Premium versions up to and including 2.27.5. The flaw is present in handling of the cats and tags query parameters, where user-supplied input is insufficiently escaped and incorporated into an existing SQL query without sufficient preparation. As a result, unauthenticated attackers can append SQL payloads to the application’s database queries, enabling time-based blind SQL injection and database information extraction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept exploit for CVE-2025-4396, targeting a time-based blind SQL injection in the Relevanssi 4.24.4 WordPress plugin. It contains two files: a README describing the vulnerability, exploitation constraints, and sqlmap usage; and a single Python exploit script, asy.py, which is the operational entry point. The exploit is a real web-based SQL injection tool, not merely a detector. The Python script uses aiohttp and asyncio to send sequential HTTP GET requests to a target WordPress instance at http://localhost:31337/, placing the injection in the 'cats' parameter while keeping 's=test' as a normal parameter. Its main purpose is to extract the wp_users.user_pass value for user ID 1, assumed to be the admin account. A notable aspect of the exploit is that it is tailored for hardened or filtered environments. Instead of standard comma-based SQL syntax such as SUBSTR(str,pos,len) or IF(cond,true,false), it uses comma-less syntax 'SUBSTR(... FROM pos FOR 1)' and 'CASE WHEN ... THEN SLEEP(...) ELSE 1 END'. This is intended to bypass comma filtering and avoid false positives caused by greedy evaluation of SLEEP() in some MySQL execution contexts. Operationally, the script performs a binary search over printable ASCII values (32-126) for each character position from 1 to 34, measuring response time to determine whether the injected condition is true. It uses a single TCP connection (aiohttp connector limit=1) to prevent overlapping delays that would corrupt timing-based inference. The result is progressive recovery of a standard 34-character WordPress phpass hash. The README also documents an alternative automated approach using sqlmap with tamper scripts (commalessmid, if2case, between), technique restriction to time-based injection, and single-threaded execution. It further notes that the extracted hash can be cracked offline with hashcat mode 400. Overall, the repository structure is minimal but coherent: documentation plus one working exploit script. The exploit capability is credential hash extraction via time-based blind SQL injection against a vulnerable WordPress/Relevanssi deployment.
This repository is a small Python exploit toolkit centered on CVE-2025-4396, described as an unauthenticated time-based blind SQL injection in the WordPress Relevanssi plugin via the cats parameter. It contains three functional files: two network exploitation scripts and one local post-exploitation/offline cracking helper, plus a README. The main exploit capability is remote extraction of a WordPress user's password hash from the wp_users table by sending crafted HTTP GET requests whose response timing reveals true/false SQL conditions. CVE_2025_4396.py performs linear character-by-character extraction over a fixed charset tailored to WordPress 6.8+ hashes, using SLEEP() and ASCII(SUBSTRING(...)=value) logic and a double-verification anti-jitter step. CVE_2025_4396_Stealth.py implements the same overall goal but uses binary search on printable ASCII with greater-than comparisons, reducing request volume and making extraction faster and somewhat stealthier. Both scripts disable TLS verification warnings, accept a target URL and user ID, and are intended to recover the user_pass hash for a chosen account. Auto_Crack.py is not a network exploit; it is a companion utility for offline cracking of recovered WordPress 6.8+ $wp$ hashes. It strips the custom $wp prefix, reproduces the WordPress prehash pipeline using HMAC-SHA384 with the fixed salt wp-sha384 followed by Base64, writes transformed candidates and a mapping file, invokes Hashcat in bcrypt mode, and then resolves any cracked prehash back to the original plaintext password. Overall, the repository structure and purpose are coherent: exploit the vulnerable Relevanssi search parameter to exfiltrate a password hash, then automate cracking of that hash locally.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.