CVE-2025-10915: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-10915 is a missing authorization vulnerability in the Dreamer Blog WordPress theme (versions through 1.2) that allows authenticated subscribers — and potentially unauthenticated users — to perform arbitrary plugin installations. The vulnerability was publicly disclosed on December 23, 2025, and assigned a CVE on January 13, 2026. It was discovered and reported by researcher Khaled Alenazi (Nxploited) and verified by WPScan (WPScan). CISA-ADP assigned a CVSS v3.1 base score of 9.8 (Critical), while WPScan rates it 8.8 (High) (WPScan). No fixed version is currently available.

Technical details

The root cause is a missing capability check (CWE-862) in the theme's AJAX handler install_act_plugin_custom, which fails to verify whether the requesting user has sufficient privileges before performing plugin installation actions (WPScan). This falls under OWASP Top 10 A5: Broken Access Control. Exploitation is straightforward: an attacker with at minimum a Subscriber-level WordPress account sends a crafted HTTP POST request to wp-admin/admin-ajax.php with the action=install_act_plugin_custom parameter and a target plugin slug, bypassing all authorization checks. The attack requires network access and a valid session cookie, but no administrative privileges.

Impact

Successful exploitation allows an attacker to install arbitrary plugins from the WordPress.org repository onto the target site, which can be leveraged to achieve full site compromise — including unauthorized code execution, data exfiltration, defacement, or persistent backdoor installation. The CVSS assessment reflects high impacts to confidentiality, integrity, and availability, as a malicious plugin can grant the attacker complete control over the WordPress environment (WPScan). This could further enable lateral movement within the hosting environment depending on server configuration.

Exploitability

A public proof-of-concept is available via WPScan, demonstrating exploitation with a simple curl command requiring only a valid subscriber-level session cookie (WPScan). There is no current evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Dreamer Blog theme (version ≤ 1.2) via web crawlers, WPScan, or Wappalyzer fingerprinting.
  2. Obtain Subscriber Access: Register a low-privilege subscriber account on the target WordPress site (if open registration is enabled) or use compromised credentials.
  3. Craft Malicious Request: Prepare a POST request targeting the vulnerable AJAX endpoint with the desired plugin slug:
    curl -X POST 'http://example.com/wp-admin/admin-ajax.php?action=install_act_plugin_custom' \
      -H 'Cookie: wordpress_logged_in_XXXXXXXX=USER|TIMESTAMP|HASH' \
      --data 'plugin=<malicious-or-backdoored-plugin-slug>'
  4. Install Malicious Plugin: Submit the request; the server installs the specified plugin without authorization verification due to the missing capability check.
  5. Activate and Execute: If the installed plugin can be activated (via a separate request or if auto-activated), leverage it to execute arbitrary PHP code, establish a web shell, or exfiltrate data (WPScan).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-admin/admin-ajax.php with action=install_act_plugin_custom in the request body or query string, originating from low-privilege user sessions.
  • Logs: WordPress access logs showing admin-ajax.php calls with the install_act_plugin_custom action from subscriber-level accounts; WordPress debug logs recording unexpected plugin installation events.
  • File System: Newly created plugin directories under wp-content/plugins/ that were not administratively installed; presence of unfamiliar or suspicious plugin files with recent timestamps.
  • WordPress Admin: Unexpected entries in the installed plugins list, particularly plugins not recognized by site administrators or installed outside normal change windows.

Mitigation and workarounds

There is currently no patched version of the Dreamer Blog theme available (WPScan). Site administrators should immediately deactivate and remove the Dreamer Blog theme as the primary remediation step. As interim mitigations, restrict access to wp-admin/admin-ajax.php via a Web Application Firewall (WAF) rule blocking requests with action=install_act_plugin_custom, disable open user registration to prevent unauthorized subscriber account creation, and audit installed plugins for any unauthorized additions. Monitor the theme's repository for a patched release and apply it promptly when available.

Community reactions

The vulnerability received brief coverage on social media platforms including Bluesky and Mastodon via TheHackerWire, and was indexed by multiple vulnerability aggregators shortly after disclosure (Feedly). A technical write-up was published by Infinit Security detailing the subscriber-level arbitrary plugin installation vector (Infinit Security). No major vendor statements or significant researcher debate beyond the initial disclosure have been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management