CVE-2023-3460 is a privilege escalation vulnerability in the Ultimate Member WordPress plugin affecting versions prior to 2.6.7. The plugin fails to prevent unauthenticated visitors from creating user accounts with arbitrary capabilities. As a result, an attacker can register a new account and assign elevated WordPress roles or capabilities, including administrative privileges, without authorization. The issue stems from improper restriction of privilege assignment during account creation, enabling attacker-controlled capability values to be accepted by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit for CVE-2023-3460, a critical privilege escalation vulnerability in the WordPress Ultimate Member plugin (versions <=2.6.6). The exploit is implemented in a single Python script (CVE-2023-3460.py) and is accompanied by a detailed README.md. The script automates the process of registering a new user with administrator privileges by abusing the registration form at the /register/ endpoint. It fetches the CSRF nonce, crafts a registration request with the 'wp_càpabilities[administrator]=1' parameter, and submits it to the target. If successful, an unauthenticated attacker can gain full administrative access to the WordPress site. The exploit requires Python 3 and the requests, urllib3, and beautifulsoup4 libraries. The README provides usage instructions, vulnerability details, and mitigation advice. No hardcoded endpoints or credentials are present; the target URL is supplied by the user at runtime.
This repository is a comprehensive exploitation lab for WordPress plugin vulnerabilities, primarily targeting CVE-2023-3460 (Ultimate Member <= 2.6.6 - Unauthenticated Arbitrary User Creation) and CVE-2023-10924 (Really Simple SSL plugin 2FA bypass). The structure includes Dockerfiles and docker-compose files to set up a vulnerable WordPress environment with intentional misconfigurations (SUID binaries, writable /etc/passwd, cron jobs) for privilege escalation practice. Key exploit scripts: - `exploit.py` (CVE-2023-3460): Automates the creation of a new admin user on a vulnerable WordPress instance by exploiting the Ultimate Member plugin. - `activate-plugin.py`: Automates plugin activation and page creation in WordPress. - `cve-2023-10924.py`: Exploits an endpoint in the Really Simple SSL plugin to bypass 2FA onboarding. - `Exploit_backdor/x.py`: Implements a simple HTTP server to receive file uploads, acting as a backdoor. The Docker environment is configured to facilitate privilege escalation via SUID binaries, writable /etc/passwd, and cron jobs. The repository also includes a full copy of the Ultimate Member plugin for local testing. The main attack vectors are network-based (HTTP POST requests to WordPress endpoints) and local privilege escalation within the container. Multiple fingerprintable endpoints are present, including HTTP URLs and file paths relevant to the exploitation process.
This repository contains a working exploit for CVE-2023-3460, targeting the Ultimate Member WordPress plugin (versions below 2.6.7). The exploit is implemented in Python (exploit.py) and automates the process of checking the plugin version and exploiting the registration process to create a new administrator account. It first verifies the plugin version by fetching the readme.txt file, then retrieves a registration nonce from the registration page, and finally submits a crafted registration form that grants administrator privileges to the attacker. The exploit requires the target URL as input and outputs the credentials for the newly created admin user. The repository is structured simply, with a README.md describing the exploit and a single Python script implementing the attack. The main endpoints targeted are the plugin's readme.txt for version checking and the registration page for the exploit payload.
This repository contains a Python exploit script (exploit.py) targeting CVE-2023-3460, a vulnerability in the Ultimate Member WordPress plugin (versions before 2.6.7). The exploit allows unauthenticated attackers to create new administrator accounts by abusing the registration process. The script first checks the plugin version by fetching the readme.txt file, then retrieves a registration nonce from the registration page, and finally submits a crafted POST request to the /index.php/register/ endpoint to create a new admin user. The script supports both single-target and multi-target (list-based) exploitation. The only code file is exploit.py, and the repository also includes a README.md with usage instructions. The exploit is operational and provides full admin access to vulnerable WordPress sites.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.