
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10915 is a missing authorization vulnerability in the Dreamer Blog WordPress theme (versions through 1.2) that allows authenticated subscribers — and potentially unauthenticated users — to perform arbitrary plugin installations. The vulnerability was publicly disclosed on December 23, 2025, and assigned a CVE on January 13, 2026. It was discovered and reported by researcher Khaled Alenazi (Nxploited) and verified by WPScan (WPScan). CISA-ADP assigned a CVSS v3.1 base score of 9.8 (Critical), while WPScan rates it 8.8 (High) (WPScan). No fixed version is currently available.
The root cause is a missing capability check (CWE-862) in the theme's AJAX handler install_act_plugin_custom, which fails to verify whether the requesting user has sufficient privileges before performing plugin installation actions (WPScan). This falls under OWASP Top 10 A5: Broken Access Control. Exploitation is straightforward: an attacker with at minimum a Subscriber-level WordPress account sends a crafted HTTP POST request to wp-admin/admin-ajax.php with the action=install_act_plugin_custom parameter and a target plugin slug, bypassing all authorization checks. The attack requires network access and a valid session cookie, but no administrative privileges.
Successful exploitation allows an attacker to install arbitrary plugins from the WordPress.org repository onto the target site, which can be leveraged to achieve full site compromise — including unauthorized code execution, data exfiltration, defacement, or persistent backdoor installation. The CVSS assessment reflects high impacts to confidentiality, integrity, and availability, as a malicious plugin can grant the attacker complete control over the WordPress environment (WPScan). This could further enable lateral movement within the hosting environment depending on server configuration.
A public proof-of-concept is available via WPScan, demonstrating exploitation with a simple curl command requiring only a valid subscriber-level session cookie (WPScan). There is no current evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
curl -X POST 'http://example.com/wp-admin/admin-ajax.php?action=install_act_plugin_custom' \
-H 'Cookie: wordpress_logged_in_XXXXXXXX=USER|TIMESTAMP|HASH' \
--data 'plugin=<malicious-or-backdoored-plugin-slug>'/wp-admin/admin-ajax.php with action=install_act_plugin_custom in the request body or query string, originating from low-privilege user sessions.admin-ajax.php calls with the install_act_plugin_custom action from subscriber-level accounts; WordPress debug logs recording unexpected plugin installation events.wp-content/plugins/ that were not administratively installed; presence of unfamiliar or suspicious plugin files with recent timestamps.There is currently no patched version of the Dreamer Blog theme available (WPScan). Site administrators should immediately deactivate and remove the Dreamer Blog theme as the primary remediation step. As interim mitigations, restrict access to wp-admin/admin-ajax.php via a Web Application Firewall (WAF) rule blocking requests with action=install_act_plugin_custom, disable open user registration to prevent unauthorized subscriber account creation, and audit installed plugins for any unauthorized additions. Monitor the theme's repository for a patched release and apply it promptly when available.
The vulnerability received brief coverage on social media platforms including Bluesky and Mastodon via TheHackerWire, and was indexed by multiple vulnerability aggregators shortly after disclosure (Feedly). A technical write-up was published by Infinit Security detailing the subscriber-level arbitrary plugin installation vector (Infinit Security). No major vendor statements or significant researcher debate beyond the initial disclosure have been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."