WordPress versions 3.5 through 6.8.2 allow remote attackers to infer or guess the titles of private and draft posts by sending crafted pingback.ping XML-RPC requests to the XML-RPC endpoint. The issue is an information disclosure condition in the handling of pingback requests, where application behavior exposes whether a supplied target corresponds to an existing private or draft post title. The available information indicates this affects the pingback.ping method specifically and results in disclosure of otherwise non-public post title information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a 194-byte README and one 3,013-byte Python proof-of-concept script. XMLRPC-Pingback.py accepts source_uri, target_uri, and a wordlist, builds XML-RPC pingback.ping method calls, and POSTs them with a text/xml content type. For each wordlist entry it appends the entry to the supplied target URI prefix, prints a truncated response, and stops after its success predicate is met. The README claims CVE-2025-54352 affects WordPress 3.5 through 6.8.2. The implementation is incomplete for practical targeting: the XML-RPC destination is fixed to the reserved example.com host rather than derived from command-line input. In addition, its success checker rejects XML fault documents but then requires the literal string 'pingback.ping' in the response, which may not match normal successful XML-RPC responses. No command-execution, shell, persistence, or post-exploitation payload is present.
Repository contains a small Python proof-of-concept for abusing the WordPress XML-RPC pingback mechanism (README claims CVE-2025-54352 affecting WordPress 3.5 through 6.8.2). Structure: (1) README.md describing the PoC; (2) XML-Pingback.py implementing the attack. XML-Pingback.py takes three CLI arguments: source_uri, target_uri, and a wordlist file. It constructs an XML-RPC <methodCall> for pingback.ping with params (source_uri, target_uri+<wordlist_entry>) and POSTs it with Content-Type: text/xml. It checks for success by parsing the XML response and ensuring no <fault> element exists and that the response text contains 'pingback.ping'. On a perceived success, it prints the target and response snippet, appends the successful word to a 'title' string, and stops iterating that wordlist pass. Notable limitation: the actual XML-RPC endpoint is hardcoded to http://example.com/xmlrpc.php, so the user must modify the script to point at the intended WordPress target. The script is primarily a network PoC to trigger pingback requests rather than a full weaponized exploit (no reverse shell or post-exploitation).
This repository contains a proof-of-concept (POC) exploit for the XML-RPC pingback vulnerability (CVE-2025-54352) affecting WordPress versions 3.5 through 6.8.2. The main file, XML-Pingback.py, is a Python script that automates sending crafted XML-RPC pingback requests to a target WordPress site's xmlrpc.php endpoint. The script takes three arguments: a source URI, a target URI, and a wordlist file. For each entry in the wordlist, it appends the word to the target URI and sends a pingback request, checking the response for success. The script is designed to demonstrate the vulnerability and is not weaponized; it is a POC. The only hardcoded endpoint is a placeholder (http://example.com/xmlrpc.php), which users are expected to replace with the actual target. The repository structure is simple, consisting of the exploit script and a README file describing the vulnerability and affected versions.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2025-54352, targeting WordPress via a timing side-channel vulnerability in the XML-RPC pingback.ping method. The repository contains a README with setup and usage instructions, and a single JavaScript file (test.js) implementing the exploit logic. The exploit works by sending multiple crafted XML-RPC requests to the /xmlrpc.php endpoint of a WordPress instance, using regexes in the fragment to brute-force the title of a private or draft post. By measuring the response times, the script infers the correct characters of the post title. The attack is fully automated and requires only the target WordPress URL and a prefix (optional) as input. The code is a functional PoC and does not include weaponized features or post-exploitation payloads. The main fingerprintable endpoints are the local WordPress instance (http://localhost:8080/xmlrpc.php) and an external timing endpoint (http://httpstat.us/200?sleep=1000).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.