CVE-2025-15403Patch

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' setting. This makes it possible for unauthenticated attackers to injecting an empty slug into the order parameter, and manipulate the plugin's menu generation logic, and when the admin menu is subsequently built, the plugin adds 'manage_options' capability for the target role. Note: The vulnerability can only be exploited unauthenticated, but further privilege escalation requires at least a subscriber user.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-04); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-04: 1Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-24: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-08-24: 102-0408-24
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-08-241
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-15403 - critical 🚨 RegistrationMagic <= 6.0.7.1 - Privilege Escalation > RegistrationMagic WordPress plugin <= 6.0.7.1 contains a privilege escalation caused ... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-15403 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a privilege escalation vulnerability (CVE-2025-15403) in RegistrationMagic up to version 6.0.7.1 and points to a resource likely containing a PoC.

    040134830
    1.3K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical WordPress Security Alert — CVE-2025-15403 A privilege escalation flaw was disclosed in the RegistrationMagic plugin (≤ 6.0.7.1) that lets unauthenticated attackers abuse an AJAX action to manipulate settings and grant manage_options admin rights to lower-privilege accounts. This can lead to full site takeover if a subscriber account is later compromised. https://nvd.nist.gov/vuln/detail/CVE-2025-15403 Severity: CRITICAL (CVSS 3.1 9.8) — exploitable over the network with no login required for initial manipulation. ✅ Mitigation: • Update RegistrationMagic to a patched version above 6.0.7.1 immediately • Audit user roles for unauthorized admin rights • Scan for injected admin access or hidden malware artifacts 🛡️ Protect your WordPress business with full perimeter scanning & monitoring: 👉 https://quttera.com/wordpress-malware-scanner Secure your website with full perimeter security #WordPress #CVE #PluginSecurity #PrivilegeEscalation #WebSecurity #eCommerceSecurity #WordPressSecurity #Malware #CVE

    Post summary

    CVE-2025-15403 is a critical privilege escalation vulnerability in RegistrationMagic that allows unauthenticated users to grant admin rights. Update the plugin to a patched version above 6.0.7.1 and audit user roles to mitigate the risk.

    0000068
    37 followersView on X

Explore more