CVE-2014-4725

EXPLOITED

MailPoet Newsletters <2.6.7 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-4725 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including Metasploit, AnotherSec, Marc-Alexandre Montpas, Christian Mehlmauer, including a Metasploit module exploits/unix/webapp/wp_wysija_newsletters_upload.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress MailPoet (wysija-newsletters) plugin versions before 2.6.8. It bypasses access controls by leveraging PHP's $_REQUEST variable handling to upload a malicious ZIP file containing a PHP payload.

Description

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/33991

This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress MailPoet (wysija-newsletters) plugin versions before 2.6.8. It bypasses access controls by leveraging PHP's $_REQUEST variable handling to upload a malicious ZIP file containing a PHP payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress MailPoet (wysija-newsletters) < 2.6.8
No auth needed
Prerequisites: Target running vulnerable WordPress plugin · Access to wp-admin/admin-post.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by AnotherSec · poc
https://github.com/AnotherSec/CVE-2014-4725

This repository contains a Python script to scan for and exploit CVE-2014-4725, a vulnerability in the MailPoet/Wysija Newsletters WordPress plugin. The exploit uploads a malicious ZIP file to vulnerable targets, achieving remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress with MailPoet/Wysija Newsletters plugin
No auth needed
Prerequisites: Target running vulnerable WordPress plugin · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/Pwdnx1337/MASS-CVE-2014-4725

This repository contains a functional exploit for CVE-2014-4725, targeting the MailPoet/Wysija Newsletters plugin in WordPress. The exploit includes both scanning and exploitation capabilities, allowing for the upload of a malicious ZIP payload to vulnerable targets.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress with MailPoet/Wysija Newsletters plugin
No auth needed
Prerequisites: Target must be running WordPress with vulnerable MailPoet/Wysija Newsletters plugin · Target must be accessible via HTTP
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Marc-Alexandre Montpas, Christian Mehlmauer · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_wysija_newsletters_upload.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in the WordPress MailPoet Newsletters plugin (wysija-newsletters) before version 2.6.8. It bypasses access checks by leveraging PHP's $_REQUEST variable handling to upload a malicious ZIP file containing a PHP payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress MailPoet Newsletters (wysija-newsletters) < 2.6.8
No auth needed
Prerequisites: Target running vulnerable version of wysija-newsletters · Access to WordPress admin post endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.5968
EPSS Percentile 99.0%

Details

VulnCheck KEV 2022-12-05
CWE
CWE-287
Status published
Products (50)
mailpoet/mailpoet_newsletters 0.9
mailpoet/mailpoet_newsletters 0.9.1
mailpoet/mailpoet_newsletters 0.9.2
mailpoet/mailpoet_newsletters 0.9.6
mailpoet/mailpoet_newsletters 1.0
mailpoet/mailpoet_newsletters 1.0.1
mailpoet/mailpoet_newsletters 1.1
mailpoet/mailpoet_newsletters 1.1.1
mailpoet/mailpoet_newsletters 1.1.2
mailpoet/mailpoet_newsletters 1.1.3
... and 40 more
Published Jul 27, 2014
Tracked Since Feb 18, 2026