CVE-2021-42362 is an arbitrary file upload vulnerability in the WordPress Popular Posts plugin affecting versions up to and including 5.3.2. The issue is caused by insufficient validation of uploaded file types in the plugin's ~/src/Image.php component. An authenticated attacker with contributor-level privileges or higher can upload a malicious file through the vulnerable upload functionality. Because the uploaded file can be placed on the server and subsequently executed in a web-accessible context, successful exploitation can lead to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains an exploit for CVE-2021-42362, targeting the WordPress Popular Posts plugin. The exploit is implemented in a single Python script (Script.py) and is accompanied by a README.md describing the vulnerability. The script automates the process of authenticating to a WordPress site (requiring contributor-level credentials), uploading a PHP web shell disguised as a GIF file to a temporary file hosting service (filebin.net), and then leveraging the vulnerable plugin to link the uploaded shell to a new post's custom field. The script also checks for required server configuration (PHP GD extension), retrieves necessary tokens/nonces for plugin actions, and simulates post views to ensure the malicious post appears in the popular posts list. The end result is a web-accessible PHP shell on the target, enabling remote command execution. The code is operational and automates the full exploitation chain, but is not part of a larger framework. The main attack vector is web-based, exploiting authenticated file upload and plugin misconfiguration. Several fingerprintable endpoints are present, including the WordPress login, admin, REST API, and the filebin.net service used for temporary file storage.
This repository contains a single Metasploit module (wp_popular_posts_rce.rb) that exploits an authenticated remote code execution vulnerability (CVE-2021-42362) in the WordPress Popular Posts plugin versions <= 5.3.2. The exploit requires valid WordPress credentials and the 'gd' PHP extension on the target. The attack works by reconfiguring the plugin to accept an arbitrary image URL, uploading a post, and manipulating the plugin's popularity ranking to trigger a cache refresh. The plugin then downloads a malicious PHP payload (disguised as a GIF) from the attacker's web server and stores it in the uploads directory. The module then triggers the payload, resulting in remote code execution as the web server user. The exploit is weaponized, supporting customizable PHP payloads (defaulting to Meterpreter reverse shell), and is fully integrated into the Metasploit framework. The main endpoints involved are the WordPress root path and the uploads directory where the payload is stored and executed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.