CVE-2025-54352
LOWWordPress 3.5-6.8.2 - Unauthenticated Private Post Title Exposure via Pingback XML-RPC Requests
Title source: llmExploitation Summary
EIP tracks 5 public exploits for CVE-2025-54352. PoCs published by mufasa-noir, mufasa4o4, crypcky.
AI-analyzed exploit summary This repository contains a functional Python script that exploits the XML-RPC Pingback vulnerability (CVE-2025-54352) in WordPress versions 3.5 through 6.8.2. The script sends crafted XML-RPC pingback requests to a target endpoint, potentially enabling SSRF or DDoS amplification attacks.
Description
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
Exploits (5)
This repository contains a functional Python script that exploits the XML-RPC Pingback vulnerability (CVE-2025-54352) in WordPress versions 3.5 through 6.8.2. The script sends crafted XML-RPC pingback requests to a target endpoint, potentially enabling SSRF or DDoS amplification attacks.
This repository contains a functional Python script that exploits the XML-RPC Pingback vulnerability in WordPress (CVE-2025-54352). The script sends crafted XML-RPC requests to a target WordPress site, leveraging the pingback.ping method to potentially trigger SSRF or other attacks.
This repository contains a functional Python script that exploits the XML-RPC Pingback vulnerability in WordPress (CVE-2025-54352). The script sends crafted XML-RPC requests to a target WordPress site, leveraging the pingback.ping method to potentially trigger SSRF or other attacks.
This PoC exploits a timing-based side-channel vulnerability in WordPress's XML-RPC pingback functionality to leak private/draft post titles. It uses a brute-force approach with timing analysis to infer characters of the title.
This repository contains a functional PoC for CVE-2025-54352, which exploits an information leak vulnerability in WordPress to retrieve the titles of private or draft posts. The PoC uses Node.js to send crafted requests to a WordPress instance and extract sensitive data.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N