The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository demonstrates a Cross-Site Request Forgery (CSRF) to Arbitrary File Upload vulnerability in the Bread & Butter IO WordPress plugin (<= 7.10.1321). The exploit leverages the lack of CSRF protection in the 'uploadImage' AJAX handler, allowing an attacker to trick an authenticated administrator into uploading a malicious PHP file (web shell) to the server. The repository contains three files: a detailed README.md explaining the vulnerability and exploitation steps, a simple proof-of-concept exploit (attack.html) that submits a crafted form to the vulnerable AJAX endpoint, and a more realistic phishing lure (email-lure.html) that embeds the exploit in an email template. The main attack vector is browser-based CSRF, targeting the WordPress AJAX endpoint at '/wp-admin/admin-ajax.php'. If successful, the attacker can access the uploaded web shell at '/wp-content/uploads/[year]/[month]/test.php' and execute arbitrary commands via the 'cmd' parameter. The exploit is a proof-of-concept and does not include advanced evasion or automation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.