CVE-2025-68860 is an authentication-bypass vulnerability in the WordPress Mobile Builder plugin affecting versions through 1.4.2. The flaw permits authentication abuse through an alternate path or channel, potentially enabling unauthenticated remote access to functionality or data that should be protected by authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a WordPress plugin exploit for CVE-2025-68860 (Mobile Builder <= 1.4.2) plus a Nuclei template for version detection. Structure: - CVE-2025-68860.py: Python exploit script, but it is PyArmor-obfuscated (trial build). This prevents reliable extraction of exact request paths/headers from the code itself via static review; however, the README describes the intended behavior. - CVE-2025-68860.yaml: Nuclei detection template that requests /wp-content/plugins/mobile-builder/readme.txt and extracts the plugin version from the "Stable tag" field. - README.md: Detailed exploit description and step-by-step flow. - LICENSE: MIT. Exploit purpose/capabilities (per README): - Leverages broken authentication caused by a hardcoded JWT secret ("example_key") in the Mobile Builder plugin. - Generates a forged HS256 JWT for user_id=1 (administrator). - Uses the token to call WordPress REST API endpoints (notably /wp-json/wp/v2/users/me) to confirm admin access. - Sends a POST to /wp-json/wp/v2/users to create a new administrator account (hardcoded example: username dedsec1337, password admin, email dedsec1337@gmail.com), resulting in full site takeover. Overall, this is an operational takeover exploit (creates an admin user) paired with a lightweight detection template to fingerprint vulnerable installations by plugin version.
This repository contains a fully automated exploit for CVE-2025-68860, targeting the WordPress Mobile builder plugin (versions <= 1.4.2). The main script, CVE-2025-68860.py, is a Python 3 program that exploits a broken authentication vulnerability by generating a valid JWT token as the admin user (user_id=1) using a known static secret. It then authenticates to the WordPress REST API and creates a new administrator account with preset credentials (username: Nxploited, password: admin, email: adminnx@admin.com). The script provides clear, colorized output and prints the new credentials and full API response upon success. The repository also includes a README with detailed usage instructions, a license file, and a requirements.txt listing the necessary Python dependencies (pyjwt, requests, colorama). The exploit is operational and provides immediate admin access to vulnerable targets.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.