CVE-2025-6254 is a privilege escalation vulnerability affecting the Doctreat Core plugin for WordPress in all versions up to and including 1.6.8. The flaw is caused by improper privilege management in the doctreat_process_registration() function, which does not correctly restrict the roles that can be assigned during user registration. As a result, an unauthenticated remote attacker can submit a registration request that results in creation of an administrator-level account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single standalone Python exploit script, CVE-2025-11740.py, despite the filename not matching the vulnerability identifier used in the code. The script claims to target CVE-2025-6254 affecting Doctreat Core <= 1.6.8 on WordPress and performs unauthenticated privilege escalation by creating administrator accounts. Structure and operation: the script first normalizes targets and auto-detects HTTP vs HTTPS by probing the site root. It then attempts to harvest a registration nonce from either the homepage (/) or /wp-login.php using several regex patterns matching ajax_nonce-style variables. If a nonce is found, it submits a POST request to /wp-admin/admin-ajax.php with action doctreat_process_registration and registration fields including user_type=administrator. Usernames and emails are generated per target, while the password is hardcoded as Password@1234!. Capabilities: it supports single-target mode (-u) and bulk mode from a file (-f), uses a ThreadPoolExecutor for concurrent exploitation, tracks progress, and saves successful compromises to success_admin.txt and failures to failed_targets.txt. The exploit is operational rather than a mere proof of concept because it includes full account-creation logic and bulk automation, but payload customization is limited. Notable findings: the exploit disables TLS certificate warnings and verification, making it tolerant of invalid HTTPS deployments. Success detection is simplistic, relying on the presence of the string 'success' in the response body. No post-exploitation shell or code execution payload is included; the primary outcome is unauthorized administrator account creation on vulnerable WordPress/Doctreat installations.
This repository is a small standalone exploit PoC for CVE-2025-6254 affecting the WordPress Doctreat Core plugin <= 1.6.8. It contains two files: a Python exploit script and a README describing the vulnerability, impact, and usage. The main script, CVE-2025-6254_exploit.py, is the clear entry point and performs a web-based unauthenticated privilege escalation attack. The exploit workflow is straightforward: it accepts a target base URL from argv (defaulting to http://localhost:8085), attempts to scrape an exposed Doctreat ajax nonce from the site root or /wp-login.php using several regex patterns, then submits a POST request to /wp-admin/admin-ajax.php with action=doctreat_process_registration. The POST body includes normal registration fields plus user_type=administrator, which is the core role-injection primitive. If the response contains the string 'success', the script reports the generated administrator credentials and the WordPress login URL. Capabilities are limited but impactful: the code does not deliver shellcode or post-exploitation automation, but it does create a privileged admin account, enabling follow-on compromise through normal WordPress administration features. The exploit is operational rather than a mere detector because it actively performs account creation. It is not part of a larger exploit framework. Notable implementation details: nonce extraction is opportunistic and depends on the active Doctreat theme exposing ajax_nonce in public JavaScript output; the script also notes fallback regexes for alternate nonce names. Credentials are partly randomized (username/email suffix) while the password is hardcoded as Password@1234!. Error handling is basic, with connection and generic exception catches. The README claims results are saved to result.txt, but that behavior is not present in the actual code.
Repository contains a single Python exploit script and a short README with usage examples. The main file, CVE-2025-6254.py, is a standalone exploit for CVE-2025-6254 affecting Doctreat Core <= 1.6.8 on WordPress. Its purpose is unauthenticated privilege escalation by abusing exposed registration logic to create a new account with an attacker-chosen role, defaulting to administrator. Structurally, the script defines constants for thread count, timeout, default role, candidate AJAX action names, and candidate registration paths. It builds a requests.Session with TLS verification disabled and a browser-like User-Agent, then generates random credentials for each attempt. It probes several registration-related URLs to extract a nonce using regex patterns, then submits registration requests to /wp-admin/admin-ajax.php using multiple possible action names. Success is determined by HTTP 200 responses, JSON fields such as success/user_id, or success-like HTML text. Operationally, the exploit supports both single-target mode (-u/--url) and bulk mode (-f/--file) with multithreading via ThreadPoolExecutor. It maintains thread-safe counters and output handling, deduplicates target lists, and appends successful results to a file. This is not merely a detector: it attempts actual account creation and privilege assignment. Based on the visible code, the exploit is operational but not part of a larger framework.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.