
CVE-2025-5815: An unauthenticated vulnerability in the WordPress Traffic Monitor plugin (≤ 3.2.2) allowing remote attackers to disable bot logging via an exposed AJAX action without requiring authentication.
This repository features a Nuclei template specifically designed to detect an Unauthenticated Bot Logging Disable Vulnerability (CVE-2025-5815) in the Traffic Monitor WordPress plugin. This issue allows unauthenticated attackers to remotely disable bot logging via a vulnerable AJAX action.
CVE-2025-5815 arises from missing authentication and authorization checks on the tfcm_set_bot_flags AJAX action in the Traffic Monitor plugin for WordPress. This allows remote attackers to tamper with plugin settings, disabling bot logging without requiring login credentials — leading to evasion of activity monitoring on affected WordPress sites.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NThis Nuclei template attempts to exploit the vulnerable AJAX endpoint by sending an unauthenticated request to admin-ajax.php with the action=tfcm_set_bot_flags parameter and checks for a success confirmation in the response body.
To use this template with Nuclei, make sure Nuclei is installed on your system. Then run the following command:
nuclei -t path/to/CVE-2025-5815.yaml -u <target_url>
Replace path/to/CVE-2025-5815.yaml with the actual path to your template file and <target_url> with the target website URL.
This template was developed by RootHarpy. For inquiries, collaboration, or contributions, feel free to connect via GitHub.