The Likes and Dislikes Plugin for WordPress through version 1.0.0 contains an SQL injection vulnerability in its handling of the post parameter. Insufficient escaping of attacker-supplied input and insufficient preparation of the existing SQL query allow additional SQL queries to be appended to an existing query.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-5287, a time-based blind SQL injection vulnerability in the WordPress Likes and Dislikes Plugin (version 1.0.0 and below). The main file, CVE-2025-5287.py, is a Python script that sends a crafted POST request to the /wp-admin/admin-ajax.php endpoint of a target WordPress site, exploiting the 'my_likes_dislikes_action' AJAX action via the 'post' parameter. The script measures the response time to determine if the SQL injection is successful (i.e., if the server delays its response due to the injected SLEEP command). The exploit does not require authentication and is designed for testing and verification of the vulnerability. The repository also includes a README.md with usage instructions, plugin details, and search tips for finding vulnerable targets. No hardcoded endpoints or credentials are present; the script requires the user to specify the target URL.
This repository contains a Python proof-of-concept exploit for CVE-2025-5287, a time-based blind SQL injection vulnerability in an unspecified WordPress plugin. The main file, CVE-2025-5287.py, is a multi-threaded script that reads a list of target base URLs from a user-supplied file and attempts to exploit the vulnerability by sending specially crafted POST requests to the /wp-admin/admin-ajax.php endpoint. The payload leverages the SLEEP() SQL function to induce measurable delays, allowing the script to determine if the target is vulnerable based on response times. The script supports proxy configuration, adjustable thread count, and timeout/fudge factors for timing accuracy. The README.md provides usage instructions and describes the exploit's purpose. No hardcoded IPs or domains are present; the script is designed for broad scanning of user-supplied targets.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.