WordPress Core is vulnerable to stored cross-site scripting (XSS) in versions up to 6.5.2 due to insufficient output escaping of user display names rendered by the Avatar block. According to the provided content, an authenticated attacker with contributor-level access or higher can inject arbitrary script into pages, and that script executes when other users view the affected page. The content also states that unauthenticated attackers may be able to inject arbitrary script through pages that include the comment block and display the comment author’s avatar, because the comment author display name is rendered without proper escaping in that context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains an exploit for CVE-2024-4439, a stored Cross-Site Scripting (XSS) vulnerability in WordPress Core up to version 6.5.1. The exploit is implemented in a single code file (PoC.py), which is actually JavaScript code (despite the .py extension) that demonstrates how to inject a PHP webshell payload into the WordPress Avatar block via a vulnerable REST API endpoint. The exploit first sends a crafted POST request to the vulnerable endpoint to store the payload, then accesses the injected webshell to execute arbitrary commands, such as spawning a reverse shell. The README.md provides background on the vulnerability and credits. The main attack vector is network-based, targeting publicly accessible WordPress installations. The exploit is operational, as it provides a working payload and demonstrates post-exploitation command execution.
This repository contains a Python proof-of-concept (PoC) exploit for CVE-2024-4439, a cross-site scripting (XSS) vulnerability in WordPress. The main file, CVE-2024-4439.py, allows an attacker to inject XSS payloads into two different fields: the comment author field (via /wp-comments-post.php) and the profile first_name field (via /wp-admin/profile.php). The script takes a target WordPress site URL as input and attempts to post a comment and update a profile with malicious payloads. If successful, these payloads can trigger JavaScript execution in the browser of an admin or user viewing the affected fields. The repository is structured simply, with one exploit script and a brief README. No detection-only scripts or framework integration are present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.