CVE-2015-1579 is a directory traversal vulnerability in the Elegant Themes Divi theme for WordPress. The revslider_show_image action handled by wp-admin/admin-ajax.php accepts traversal sequences in its img parameter, enabling access to files outside the intended directory. The issue may duplicate CVE-2014-9734.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This is a two-file Python 2 mass-exploitation repository: a short README and `wordpressCVE-2015-1579.py`, the executable scanner/exploit. It targets CVE-2015-1579 in vulnerable WordPress Slider Revolution (RevSlider) deployments. The script accepts a Google dork and optional date period, automates Google Brazil searches with Selenium/Firefox, parses result links, stores candidates in `wordpressAFD_results.txt`, and invokes its fuzzing/download routines against each candidate. Its primary exploit capability is unauthenticated arbitrary-file disclosure through RevSlider's AJAX image action, specifically attempting to retrieve `wp-config.php`. The script also imports and uses python-nmap to inspect TCP ports 3306 and 3307 while handling downloaded configuration data and selecting targets. It is a functional operational mass scanner with a hard-coded file-disclosure objective, rather than a detection-only utility or an RCE framework module.
This repository contains a mass exploitation tool targeting WordPress sites vulnerable to CVE-2015-1579 (RevSlider file disclosure). The main script, 'wordpressCVE-2015-1579.py', is a Python program that automates the process of discovering vulnerable WordPress sites using Google dorking (via Selenium), parses the search results, and attempts to exploit the vulnerability to download the 'wp-config.php' file from each target. The tool stores discovered URLs in 'wordpressAFD_results.txt' and uses additional temporary files for managing targets. The exploit is operational, automating both reconnaissance and exploitation phases, and is capable of extracting sensitive configuration files from multiple sites in bulk. The README provides usage instructions and outlines the dependencies required for running the tool. No hardcoded IPs or domains are present, but the tool targets any WordPress site found via Google that is vulnerable to the specified CVE.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.