CVE-2015-10143

CRITICAL

Platform theme <1.4.4 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-10143. PoCs published by Marc-Alexandre Montpas, Christian Mehlmauer, including Metasploit module exploits/unix/webapp/wp_platform_exec.

AI-analyzed exploit summary This Metasploit module exploits a file upload vulnerability in the WordPress Platform theme, allowing remote code execution by uploading a malicious PHP file via an unchecked admin_init call. The payload is delivered through a multipart form data POST request.

Description

The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Marc-Alexandre Montpas, Christian Mehlmauer · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_platform_exec.rb

This Metasploit module exploits a file upload vulnerability in the WordPress Platform theme, allowing remote code execution by uploading a malicious PHP file via an unchecked admin_init call. The payload is delivered through a multipart form data POST request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Platform Theme < 1.4.4, Platform Pro < 1.6.2
Auth required
Prerequisites: WordPress admin access · Vulnerable Platform theme installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7353
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
PageLines/Platform < 1.4.4
pagelines/platform_theme < 1.4.4
Published Jul 25, 2025
Tracked Since Feb 18, 2026