
Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0
Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0
This Python script is a proof-of-concept (PoC) exploit for CVE-2025-5287, targeting a vulnerability in the WordPress Likes and Dislikes Plugin ≤ 1.0.0.
The vulnerability allows unauthenticated attackers to perform time-based blind SQL injection via the post parameter in the my_likes_dislikes_action AJAX action, potentially leading to sensitive data exposure or further exploitation.
requests libraryInstall required libraries:
pip install requests
Arguments:
--url / : Target WordPress site URL (with HTTP/HTTPS)-u--sleep / -s : Sleep time (seconds) for detecting SQL delay (default: 5)python3 CVE-2025-5287-poc.py --url http://target.com
Or with a custom sleep time:
python3 CVE-2025-5287-poc.py --url http://target.com --sleep 7
You can use Fofa to discover potentially vulnerable WordPress installations running the plugin.
Fofa Dork:
body="/wp-admin/admin-ajax.php"
Or to narrow down plugin-specific references:
body="my_likes_dislikes_action"
Search on: https://fofa.info
Md Shoriful Islam (RootHarpy)
This tool is created for educational and authorized penetration testing purposes only. Unauthorized use of this tool against systems without explicit permission is illegal.