CVE-2025-5701 affects the HyperComments plugin for WordPress in all versions up to and including 1.2.2. The vulnerability is caused by a missing capability check in the hc_request_handler function, allowing unauthenticated attackers to perform unauthorized modification of site data. Specifically, an attacker can update arbitrary WordPress options without authentication. By changing security-relevant options such as enabling user registration and setting the default registration role to administrator, an attacker can create a new administrative account and fully compromise the affected WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a minimal PoC-style mass exploitation script for CVE-2025-5701. Structure: - README.md: states "CVE-2025-5701 Unauthenticated Privilege Escalation Exploit". - exploit.py: Python script that reads a list of targets and concurrently sends HTTP POST requests. Core behavior (exploit.py): - Normalizes each target to include a scheme (defaults to http://). - Builds target endpoint: <target>/wp-admin/index.php?hc_action=update_options. - Sends a POST with Content-Type application/x-www-form-urlencoded and a single parameter "data" containing JSON: {"default_role":"administrator","users_can_register":"1"}. - If response is HTTP 200 and body contains "success" (case-insensitive), it reports success and instructs to visit <target>/wp-login.php?action=register; it also appends that URL to vuln_results.txt. - Uses ThreadPoolExecutor for mass scanning/exploitation with user-supplied thread count; disables TLS verification warnings and sets verify=False. Exploit capabilities: - Unauthenticated remote configuration modification on a WordPress admin endpoint (as implemented by some plugin/theme handler for hc_action=update_options). - Privilege escalation by changing site-wide registration settings so that any new registration becomes an administrator. - Mass-targeting support via multithreading and target list input. Notable limitations/assumptions: - No explicit detection beyond checking for HTTP 200 and the substring "success". - Does not automatically create the admin account; it enables a follow-on manual (or separate automated) registration step. - The vulnerable component is not identified by name in the repo; only the WordPress path and hc_action parameter are referenced.
This repository contains a Python exploit script (CVE-2025-5701.py) targeting a critical privilege escalation vulnerability (CVE-2025-5701) in the HyperComments WordPress plugin (versions <= 1.2.2). The exploit leverages an unauthenticated endpoint (/wp-admin/index.php?hc_action=update_options) to modify WordPress options, specifically enabling user registration and setting the default role for new users to 'administrator'. This allows an attacker to register a new admin account without prior authentication. The script first checks the plugin version by accessing /wp-content/plugins/hypercomments/readme.txt, verifies the exploit endpoint, and then sends a crafted POST request to perform the attack. The repository includes a README with usage instructions, a requirements.txt listing 'requests' as a dependency, and an MIT license. The exploit is operational and provides a direct path to privilege escalation on vulnerable WordPress sites.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.