A stored cross-site scripting (XSS) vulnerability exists in the WP Activity Log plugin for WordPress, affecting all versions up to and including 5.2.1. The vulnerability is due to insufficient input sanitization and output escaping on the user_id parameter, allowing unauthenticated attackers to inject arbitrary JavaScript or HTML code that will be executed in the context of an administrative user when they access a page containing the injected payload.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2024-10793, targeting the WordPress plugin 'wp-security-audit-log' version 5.2.1 or older. The exploit leverages a cross-site scripting (XSS) vulnerability to execute malicious JavaScript (xpl.js) in the context of an authenticated WordPress admin session. The repository provides a full local test environment using Docker Compose, simulating both the victim (goodcms.lab) and attacker (attacker.com) infrastructure. The main exploit workflow is as follows: the victim visits a malicious site (attacker.com), which injects a script into the WordPress admin session via XSS. The script automates the creation of a new privileged admin user, deletes all other admins, changes the admin profile, uploads a PHP shell, and logs out users. The exploit provides the attacker with full administrative access and remote shell capability on the target WordPress instance. The repository includes setup scripts, environment configuration, and the exploit code (PHP and JavaScript). Key endpoints include the local WordPress instance, the attacker's server for payload delivery, and the shell access URL. The exploit is operational and demonstrates a complete account takeover and remote code execution chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.