
Graphical exploit for CVE-2025-3102 in WordPress SureTriggers plugin, enabling unauthenticated admin user creation via API. Includes vulnerable site identification and automated exploitation.
Vanda CVE-2025-3102 💣
Exploit with graphical interface for vulnerability CVE-2025-3102 in the WordPress plugin SureTriggers (<= 1.0.78).
🚀 FEATURES
🧠 CVE DETAILS Vulnerability CVE-2025-3102 allows admin creation without authentication via the SureTriggers API. This occurs when the plugin is installed and not properly configured with an API key.
This means any attacker can exploit the flaw and gain administrative privileges on vulnerable sites, without needing authentication! 😱
🖥️ HOW TO USE
Clone the repository 📂 Clone the repository to your computer: git clone https://github.com/itsismarcos/vanda-CVE-2025-3102.git Navigate to the project directory: cd vanda-CVE-2025-3102
Install dependencies 🛠️ Install the necessary dependencies to run the exploit: pip install -r requirements.txt
Run the program 🏃♂️ Run the program with the command: python3 vanda-CVE-2025-3102.py
Check the logs 📝
The program will save results in .txt files, indicating vulnerable sites and, if applicable, sites where the exploitation was successful.
📹 DEMONSTRATION VIDEO
Watch the video below to see the exploit in action 🎥: Watch the demonstration video
💡 AUTHOR This project was created by: Marcos Roberto (aka VandaTheGod) 👑
You can find me on GitHub: https://github.com/itsismarcos