CVE-2025-15445Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged operations. An attacker can install and activate a from a user-supplied URL, leading to arbitrary PHP code execution, and also import demo content that rewrites site configuration, including Restaurant Cafeteria WordPress theme through 0.4.6_mods, pages, menus, and front page settings.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-28: 3Technical Details · 2026-03-28: 203-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-15445 🚨 Risk Level: Unknown 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-15445 #CVE-2025-15445 #CVE #Wordpress #CyberSecurity #InfoSec https://t.co/7M1oQhVcAm

    Post summary

    The tweet announces CVE-2025-15445 for WordPress, links to its NVD entry, but provides no further technical or exploitation details.

    00000183
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15445 The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subsc… https://www.cve.org/CVERecord?id=CVE-2025-15445

    Post summary

    CVE-2025-15445 reveals that the Restaurant Cafeteria WordPress theme (≤0.4.6) exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged‑in user to exploit the vulnerability.

    00000124
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15445 - Restaurant Cafeteria <= 0.4.6 - Subscriber+ Arbitrary Plugin Installation/Activation Intel Report: https://ift.tt/g4mXt57

    Post summary

    A new vulnerability (CVE-2025-15445) in Restaurant Cafeteria version ≤0.4.6 permits arbitrary plugin installation for subscribers, with no evidence of exploitation, patch, or PoC provided.

    0000087
    283 followersView on X

Explore more