A vulnerability in WordPress through version 4.9.2 allows unauthenticated attackers to cause a denial of service by abusing the script-loader.php functionality. Attackers can enumerate and repeatedly request a large number of registered JavaScript files, leading to excessive resource consumption on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2018-6389, a Denial of Service vulnerability in WordPress Core versions up to 4.9.4. The main file, 'wordpress-cve-2018-6389.py', is a standalone script that launches a multi-threaded attack against the '/wp-admin/load-scripts.php' endpoint of a target WordPress site. The script generates a large number of HTTP GET requests with randomized user agents and referers, overwhelming the server and potentially causing a DoS condition. The script is configurable via command-line arguments for the target URL and the number of threads (default: 5000). The repository also includes a README with usage instructions and a LICENSE file. No hardcoded IPs or domains are present; the user supplies the target URL. The exploit is not weaponized but serves as a functional PoC for the vulnerability.
This repository contains a Python proof-of-concept exploit for CVE-2018-6389, a denial of service (DoS) vulnerability in WordPress versions below 4.9.3. The exploit script (CVE-2018-6389.py) prompts the user for a target domain and the number of threads to use, then launches multiple threads that continuously send HTTP GET requests to the /wp-admin/load-scripts.php endpoint with a very large 'load[]' parameter. The script randomizes the User-Agent header for each request to evade simple filtering. The README.md provides background on the vulnerability, affected versions, and references. The exploit is effective against WordPress sites that have not patched this vulnerability and can cause the site to become unresponsive. No detection or post-exploitation features are present; the script is solely for performing the DoS attack.
This repository contains a Python proof-of-concept exploit for CVE-2018-6389, a Denial of Service (DoS) vulnerability in WordPress. The main file, 'wp-dos(CVE-2018-6389).py', takes a target domain and a thread count as arguments. It constructs a URL targeting the '/wp-admin/load-scripts.php' endpoint with a very large 'load[]' parameter list, which is known to be resource-intensive for vulnerable WordPress installations. The script then spawns the specified number of threads, each sending repeated HTTP GET requests to this endpoint, aiming to exhaust server resources and disrupt service. The README provides basic usage instructions and an example. There are no hardcoded IPs or domains; the target is specified at runtime. The exploit is a simple DoS tool and does not provide post-exploitation capabilities or a customizable payload. The code is straightforward and serves as a functional demonstration of the vulnerability.
This repository is a Node.js-based proof-of-concept exploit for CVE-2018-6389, a Denial of Service vulnerability in WordPress (<=4.9.x) that abuses the /wp-admin/load-scripts.php endpoint. The exploit is structured as follows: - 'index.js' is the main script, orchestrating the attack by gathering public proxies, validating them, and then using them to send a high volume of requests to the vulnerable WordPress endpoint. The requests are crafted to load a large number of script files, maximizing server resource usage and potentially causing the site to become unresponsive. - 'websites.js' contains the list of target WordPress sites. - 'fileList.js' lists the script files to be requested from the target. - 'userAgents.js' provides a pool of user-agent strings for request randomization. - 'listener.js' allows remote control of the attack script via MQTT messages (start/stop), using the 'pm2' process manager. - The exploit requires a proxy-checker endpoint (wanCheckUrl) to validate proxies and ensure anonymity. The repository is a functional DoS tool, not a detection script, and is intended for testing the impact of CVE-2018-6389 on WordPress sites. It is not weaponized (no advanced evasion or automation features), but is operational and can be used to demonstrate the vulnerability's impact in a test environment.
This repository contains a Python-based exploit tool named 'Shiva' that targets WordPress sites vulnerable to CVE-2018-6389. The exploit leverages a flaw in the load-scripts.php endpoint, which can be abused to trigger excessive resource consumption by requesting a large number of scripts in a single request. The main script, shiva.py, is a multithreaded DoS tool that sends repeated HTTP GET requests to the vulnerable endpoint, using a long query string to maximize server load. To evade IP-based blocking, Shiva integrates with the 'proxify' library to rotate through a list of proxies, sending requests from different IP addresses. The tool is configurable via command-line arguments for the target site and number of threads. The repository also includes a README.md with usage instructions and a .whitesource configuration file. The primary attack vector is network-based, targeting the HTTP interface of WordPress installations. The only fingerprintable endpoint is the /wp-admin/load-scripts.php path, which is specific to WordPress. The exploit is operational, providing a working DoS attack but not weaponized for broader automation or integration into frameworks.
This repository contains a Python script (wpdos.py) and a README.md file. The script is an exploit for CVE-2018-6389, a Denial of Service vulnerability in WordPress (up to version 4.9.2). The exploit works by sending a large number of HTTP GET requests to the /wp-admin/load-scripts.php endpoint of a target WordPress site, with each request including a very large 'load[]' parameter listing many script names. This forces the server to process and attempt to load all these scripts, consuming significant resources and potentially causing the site to become unresponsive. The script supports multi-threading (user-specified number of threads) to maximize the request rate. The README provides usage instructions and credits. No hardcoded target endpoints are present; the user specifies the target URL as a command-line argument. The exploit is a proof-of-concept for DoS and does not provide post-exploitation capabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.