
Proof-of-concept exploit for CVE-2025-8625 targeting WordPress, with Docker-based isolated lab environment and demonstration web shell for educational security research.
This repository contains the source files for an article on Xakep.ru.
The repository contains demonstration materials intended exclusively for security research, education, and testing in isolated laboratory environments. The repository is not intended for use against systems you do not own.
docker-compose.yml — configuration for spinning up a local, isolated WordPress instance for analysis and testing.exploit/CVE-2025-8625.py — example exploit code used in the article to demonstrate the concepts. Do not use against systems you do not own or for which you do not have explicit permission.exploit/shell.php — example web shell included only to demonstrate behavior in a controlled laboratory environment.The repository is provided "as is" without any warranties. By using the materials, you agree that you are responsible for complying with applicable law. When in doubt — seek legal advice.