CVE-2022-41840 is an unauthenticated directory traversal vulnerability in the Welcart eCommerce plugin for WordPress, affecting versions up to and including 2.7.7. The vulnerability allows an attacker to manipulate file paths via crafted requests, potentially accessing files outside the intended directory structure without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single operational Python exploit (zenario_exploit.py) plus a README. It targets CVE-2022-41840 in Zenario CMS <= 9.3, exploiting an unauthenticated file upload in the AJAX handler at /zenario/ajax.php (method_call=handlePluginAJAX) by POSTing a multipart form with field name 'fileUpload' and MIME 'image/svg+xml' while actually uploading a PHP webshell. The script iterates through multiple cID values (1..3) and common instanceId values (20,1,2,3,4,5,10,15,25,30,40,50) to increase reliability. After upload, it extracts the uploaded path from the server response (prefers JSON parsing of {"files":[{"path":...}]}, falls back to regex), then verifies RCE by requesting the returned path and passing cmd=echo SHELL_TEST_OK. The embedded PHP webshell supports multiple execution primitives (system/passthru/exec/shell_exec/popen) to work around disabled functions. Post-exploitation features include basic recon commands (id/whoami/hostname/uname/pwd), an interactive HTTP webshell mode, and an option to trigger a reverse shell back to an attacker-controlled host/port while the script runs a local PTY-capable listener. No external C2 infrastructure is hardcoded; all targeting is user-supplied via --target and optional --lhost/--lport.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.