CVE-2025-4606 affects the Sala - Startup & SaaS WordPress Theme for WordPress in all versions up to and including 1.1.4. The vulnerability is caused by improper validation of a user's identity before allowing updates to account details such as the password. As a result, an unauthenticated attacker can modify arbitrary users' account credentials, including those of administrator accounts, leading to account takeover and subsequent privilege escalation within the WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (main.py) targeting CVE-2025-4606 in WordPress. The exploit automates the process of enumerating valid WordPress usernames using both the REST API (/wp-json/wp/v2/users) and author ID enumeration (/?author=<id>). Once usernames are collected, the script attempts to reset their passwords by sending POST requests to the /wp-admin/admin-ajax.php endpoint with a specific action (change_password_ajax), setting the password to a value chosen by the attacker. The script supports multi-threaded execution for efficiency. The README.md is a placeholder with only the CVE identifier. The exploit requires the attacker to provide the target URL and the new password to set. No hardcoded endpoints or credentials are present; all targets are derived from user input. The exploit is operational and can be used to compromise WordPress accounts on vulnerable installations.
This repository contains a working exploit for CVE-2025-4606, a critical unauthenticated privilege escalation vulnerability in the WordPress Sala theme (versions <= 1.1.4). The vulnerability allows an attacker to reset the password of any user, including administrators, by sending a crafted POST request to the exposed AJAX endpoint '/wp-admin/admin-ajax.php' with the action 'change_password_ajax'. The exploit is implemented in 'exp.py', a concise Python script that automates the attack by sending the required POST request with attacker-supplied credentials. The README.md provides detailed background, usage instructions, and remediation advice. The exploit requires only knowledge of a valid username on the target site and does not require authentication, making it highly impactful. The repository is well-structured, with a single exploit script and comprehensive documentation.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.