In this article

WordPress Exploits on Cybercrime Forums: What Threat Actors Are Selling

WordPress exploits are advertised, auctioned, and resold on cybercrime forums alongside high-value Windows zero-days. KELA tracked listings ranging from a USD 100 arbitrary file upload exploit for a WooCommerce plugin to a Windows privilege escalation zero-day offered at USD 50,000 per copy. This blog covers what was on sale, what the sellers got wrong about their own product, and why a CVE identifier found on a forum needs verifying before you act on it.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published September 3, 2026

WordPress exploits traded on cybercrime forums

In November and December 2025, KELA observed active discussions on cybercrime forums concerning vulnerabilities disclosed that year. Threat actors were trading exploits ranging from low-cost plugin vulnerabilities to high-value zero-day exploits targeting Windows systems. This blog looks back at the details from those observations regarding the trade of exploits for WordPress plugins and Windows drivers.

WordPress plugins continue to sit at the center of growing security discussions across underground forums. Threat actors are actively advertising, selling, and even auctioning exploits tied to both real and alleged vulnerabilities. Some listings point to newly disclosed CVEs, while others recycle older flaws under misleading identifiers. At the same time, higher-value exploits targeting Windows environments are commanding serious prices.

» Skip to the solution: Try KELA's cyber threat intelligence for free

WordPress Plugin Exploits for Sale

Discussions regarding WordPress security have intensified, with actors seeking to monetize both known and alleged zero-day vulnerabilities.

WooCommerce Designer Pro (CVE-2025-6440)

A notable instance involved an actor offering an exploit for an arbitrary file upload vulnerability in the WooCommerce Designer Pro WordPress plugin, tracked as CVE-2025-6440. The flaw carries a CVSS base score of 9.8, affects all versions up to and including 1.9.26, and requires no authentication, which is what makes a USD 100 asking price notable.

  • The Offer: The exploit was listed for USD 100. The actor claimed to have already sold one copy and intended to sell only two additional copies to maintain scarcity.
  • The Leak: The sale was disrupted when another user shared a link to a public proof-of-concept (PoC) hosted on GitHub. In response, the seller alleged that their initial buyer had leaked the exploit to the public.
  • Status: At this time, KELA has found no evidence of this vulnerability being exploited in the wild.

» Make sure you know the differences between vulnerabilities vs. threats vs. risks

"CVE-2025-34085" (Simple File List)

In addition, an actor posted a weaponized auto-exploit for the WordPress Simple File List plugin. Analysts should be aware of a discrepancy in the naming convention circulating on forums:

  • Mislabeling: This exploit is commonly circulated under the identifier “CVE-2025-34085”.
  • Reality: Reality: The CVE Numbering Authority rejected this identifier as a duplicate of CVE-2020-36847, a remote code execution flaw in the plugin's rename function that affects versions up to and including 4.2.2 and was fixed in 4.2.3. Rejection does not mean the flaw is invalid, only that it was already tracked under an earlier ID. A five-year-old, long-patched vulnerability was being sold on forums under a 2025 identifier, which is why identifiers found in underground discussions need verifying before they are acted on.

» Make sure you understand how threat actors breach and exploit your data

Zero-Day Auction: Unauthorized Email Relaying

Beyond known CVEs, KELA observed an auction for a zero-day exploit affecting a WordPress plugin with more than 3,800 active installations at the time.

  • Capabilities: The vulnerability allows an attacker to send unauthorized emails from the vulnerable site to any address. The accompanying script supports both mass and single-target mailings.
  • Origins: The actor claimed to have personally discovered the vulnerability and authored the exploit.
  • Pricing: The exploit is being auctioned with a starting bid of USD 500, bid increments of USD 100, and a "blitz" (buy-it-now) price of USD 1,500.

Cyber Threat Intelligence

Stay ahead of hidden cyber activity. KELA helps you track underground threats and uncover real risks before they impact your business.

Contact Us

High-Value Windows Exploits

While WordPress remains a popular target for quick monetization, actors are also trading high-level exploits for Windows environments.

a computer screen with a web page on it

Windows CLFS Driver (CVE-2025-60709)

An actor advertised an exploit for CVE-2025-60709, an out-of-bounds read vulnerability in the Windows Common Log File System (CLFS) driver patched in Microsoft's November 2025 Patch Tuesday. Impact: This vulnerability enables local privilege escalation by an authenticated attacker, up to SYSTEM. It carries a CVSS base score of 7.8. CLFS is a repeat target: the driver has produced multiple privilege escalation flaws that have been abused in ransomware operations, which is what gives a free release its audience.

  • Impact: This vulnerability enables local privilege escalation (LPE) by an authenticated attacker.
  • Distribution: Claiming this was their "first public release," the actor offered the exploit source code for free. They further leveraged this release to market their services, claiming the ability to develop exploits for any CVE, create malware, and produce zero-day exploits upon request.
  • Status: At the time of writing, there are no confirmed reports of CVE-2025-60709 being exploited in the wild.

Windows LPE Zero-Day

In a separate high-value thread, an actor offered a Windows local privilege escalation (LPE) zero-day alongside Remote Code Execution (RCE) exploits.

  • Terms: The actor stated they had agreed to a non-exclusive sale.
  • Pricing: Pricing: The LPE exploit was reportedly offered in two additional copies at USD 50,000 each. A later update in the thread indicated that one copy remained available.

Forum Activity Observed: Below is a snapshot of the thread offering the Windows LPE zero-day, posted under the title "[Продаю 0day] Windows LPE & Couple RCEs" ("Selling 0day").

a screen shot of a web page with a black background

» Here are reasons you need cyber threat intelligence

Conclusion

The activity observed by KELA highlights a vibrant marketplace for vulnerabilities disclosed in 2025. From low-cost WordPress plugin exploits to expensive Windows zero-days, threat actors are moving quickly to weaponize new disclosures.

Organizations are advised to patch what can be patched here: WooCommerce Designer Pro above 1.9.26, Simple File List at 4.2.3 or later, and the November 2025 Windows updates covering CVE-2025-60709. The email relaying zero-day had no fix at the time of observation, which is the case for treating forum monitoring as an early warning rather than a patch list. Remain vigilant against repackaged older vulnerabilities sold under new identifiers.

» Ready to get started? Contact us to learn more about our cyber threat intelligence services

FAQs

Are all advertised WordPress plugin exploits legitimate?

No. A listing on a cybercrime forum is a sales pitch, and sellers routinely misstate what they are offering. Some advertise working exploits for real, disclosed CVEs. Others recycle years-old flaws under new identifiers, claim exclusivity on code that is already public, or sell exploits that do not work at all. Treat any forum listing as a claim to be checked against the vendor advisory and the CVE record, not as evidence that a working exploit exists.

What does it mean when a CVE is “rejected” or duplicated?

A rejected CVE identifier is one the CVE Numbering Authority has withdrawn, most often because the same flaw was already tracked under an earlier ID. Rejection does not mean the vulnerability is fake. CVE-2025-34085, circulated on forums as a WordPress Simple File List exploit, was rejected as a duplicate of CVE-2020-36847, a remote code execution flaw in the plugin's rename function that was fixed in version 4.2.3 in 2020. Defenders should patch against the valid identifier and disregard the rejected one.

How do Windows zero-day exploits differ from WordPress plugin exploits?

Price and reach. WordPress plugin exploits target internet-facing sites, are frequently already public, and change hands for tens or hundreds of dollars. Windows privilege escalation zero-days require original research, are sold in limited copies, and have been advertised at USD 50,000 per copy. A plugin exploit gives an attacker a foothold on a website; a Windows local privilege escalation zero-day gives SYSTEM-level control on a machine inside a corporate network, which is why the two sit in different markets.