Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-5815-Nuclei-Template — CVE-2025-5815: An unauthenticated vulnerability in the WordPress Traffic Monitor plugin (≤ 3.2.2) allowing remote attackers to disable bot logging via an exposed AJAX action without requiring authentication. | Kitploit
Tools/GitHubGitHub/rootharpy/cve-2025-5815-nuclei-template
Vulnerability ScannersExploitationWeb Application ExploitationWeb SecurityPenetration TestingMisconfiguration
GitHubrootharpy/cve-2025-5815-nuclei-template

CVE-2025-5815-Nuclei-Template

CVE-2025-5815: An unauthenticated vulnerability in the WordPress Traffic Monitor plugin (≤ 3.2.2) allowing remote attackers to disable bot logging via an exposed AJAX action without requiring authentication.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

📄 Nuclei Template for CVE-2025-5815

🚀 Overview

This repository features a Nuclei template specifically designed to detect an Unauthenticated Bot Logging Disable Vulnerability (CVE-2025-5815) in the Traffic Monitor WordPress plugin. This issue allows unauthenticated attackers to remotely disable bot logging via a vulnerable AJAX action.

🔍 Vulnerability Description

CVE-2025-5815 arises from missing authentication and authorization checks on the tfcm_set_bot_flags AJAX action in the Traffic Monitor plugin for WordPress. This allows remote attackers to tamper with plugin settings, disabling bot logging without requiring login credentials — leading to evasion of activity monitoring on affected WordPress sites.

🛑 Affected Versions

  • Traffic Monitor Plugin: Versions up to and including 3.2.2

📊 CVSS Score

  • Base Score: 5.3 (Medium)

🏷️ CVSS Vector

  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

📋 Template Details

This Nuclei template attempts to exploit the vulnerable AJAX endpoint by sending an unauthenticated request to admin-ajax.php with the action=tfcm_set_bot_flags parameter and checks for a success confirmation in the response body.

🛠️ Usage Instructions

To use this template with Nuclei, make sure Nuclei is installed on your system. Then run the following command:

root@kitploit:~
nuclei -t path/to/CVE-2025-5815.yaml -u <target_url>

Replace path/to/CVE-2025-5815.yaml with the actual path to your template file and <target_url> with the target website URL.

👤 Author

This template was developed by RootHarpy. For inquiries, collaboration, or contributions, feel free to connect via GitHub.

Download Tool