CVE-2022-1386 is a Server-Side Request Forgery (SSRF) vulnerability in the Fusion Builder WordPress plugin prior to version 3.6.2, used in the Avada theme. The plugin fails to properly validate a parameter in its forms, allowing attackers to craft requests that cause the server to initiate arbitrary HTTP requests. The server's response reflects the data returned from these requests, enabling attackers to interact with internal or protected resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2022-1386, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the Fusion Builder plugin (used by the Avada WordPress theme) prior to version 3.6.2. The exploit is implemented in Python (exploit_cve_2022_1386.py) and requires the 'requests' library (requirements.txt). The script works by first fetching a required nonce from the target's /wp-admin/admin-ajax.php endpoint, then sending a specially crafted multipart/form-data POST request to the same endpoint. The payload abuses the 'fusionAction' parameter to instruct the server to make an HTTP GET request to an attacker-controlled URL (such as an Interact.sh or Burp Collaborator domain), confirming SSRF if a callback is received. The repository is structured simply, with a README providing usage instructions and background, the exploit script, and a requirements file. The exploit does not exfiltrate data but demonstrates the vulnerability by confirming server-side HTTP requests to arbitrary URLs.
This repository provides a Python proof-of-concept exploit for CVE-2022-1386, a Server-Side Request Forgery (SSRF) vulnerability in the Fusion Builder WordPress plugin (versions prior to 3.6.2). The main exploit script (CVE-2022-1386.py) allows an unauthenticated attacker to send arbitrary URLs as payloads to the vulnerable endpoint (/wp-admin/admin-ajax.php), causing the target server to make HTTP requests to attacker-controlled or internal resources. The script automates the process of obtaining a required nonce (fusion_id), crafting the necessary multipart/form-data POST request, and sending the SSRF payload. It also saves relevant data (such as the fusion_id and raw HTTP requests) to output files for later analysis. The repository includes a README with usage instructions, a detailed PoC HTTP request/response, and references to external advisories. The exploit is operational as a proof-of-concept and demonstrates the vulnerability's impact but does not include weaponized or post-exploitation features.
This repository contains a Python exploit for CVE-2022-1386, targeting the Fusion Builder WordPress plugin (versions prior to 3.6.2) and exploiting an unauthenticated SSRF vulnerability. The main file, 'exploit.py', is a standalone script that interacts with the vulnerable endpoint '/wp-admin/admin-ajax.php' on the target WordPress site. It first retrieves a required nonce ('fusion-form-nonce-0'), then submits a crafted form that causes the server to make HTTP requests to arbitrary URLs specified by the attacker. The script verifies vulnerability by checking for a known string in the response from a test URL, and if successful, allows the user to send further SSRF payloads interactively. Output and state (such as the nonce and raw requests) are saved in the 'output' directory, organized by target domain. The repository also includes a 'requirements.txt' for dependencies and a minimal 'README.md' with usage instructions. The exploit is operational, providing a working SSRF proof and interactive payload capability, but does not include advanced features such as automated exploitation chains or post-exploitation modules.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.