The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to arbitrarily choose their role, including the Administrator role, during user registration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script plus a README. The exploit targets CVE-2025-6758 affecting the WordPress theme “The Real Spaces – WordPress Properties Directory Theme” (reported vulnerable up to 3.6) where the `imic_agent_register` registration flow fails to restrict the requested role. Core capability: mass exploitation of multiple targets by sending an unauthenticated HTTP POST to each target’s WordPress AJAX endpoint (`/wp-admin/admin-ajax.php`) with `action=imic_agent_register` and `role=administrator`, along with attacker-controlled username/email/password fields. If successful, it creates a new Administrator account on the target site. Structure/purpose: - `mass-regist.py`: Main entry point. Implements URL normalization (auto-prepends scheme and appends `/wp-admin/admin-ajax.php`), concurrent scanning/exploitation with a configurable worker pool, retries, timeouts, optional SSL verification, and basic success detection. It logs to console and `exploit_log.txt`, and generates summary plus report artifacts (functions indicate JSON detailed report and a list of successful targets). - `README.md`: Describes the vulnerability, usage examples, and points to a GitHub Security Advisory. Fingerprintable targeting indicators include the fixed endpoint path `/wp-admin/admin-ajax.php` and the specific POST parameters `action=imic_agent_register` and `role=administrator`, which are strong signatures for this exploit’s traffic.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.