The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file upload in all versions up to and including 2.3.3 due to missing file type validation in the kalrav_upload_file AJAX action. An unauthenticated attacker can send crafted requests to the plugin’s AJAX handler to upload arbitrary files onto the server, which may enable remote code execution depending on where the file is written and whether the server is configured to execute the uploaded file type.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
wp-admin/admin-ajax.php invoking the kalrav_upload_file action (e.g., WAF rules/rate-limits). Enforce server-side hardening to prevent execution of uploaded files in upload directories (e.g., disable PHP execution in wp-content/uploads and any plugin-controlled upload paths).Patch, then assume compromise.
kalrav_upload_file AJAX upload handler.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script and a README describing CVE-2025-13374 affecting the WordPress Kalrav AI Agent plugin (<= 2.3.3). The exploit performs an unauthenticated arbitrary file upload by POSTing a multipart form to the WordPress AJAX endpoint `/wp-admin/admin-ajax.php` with `action=kalrav_upload_file`. It uploads a PHP webshell (`shell.php` with `system($_GET["cmd"])`), parses the JSON-like response to extract the returned `url` field, normalizes escaped slashes, prints the shell URL, and then verifies code execution by requesting `?cmd=whoami` and printing the output. The README explains the root cause: the plugin registers `wp_ajax_nopriv_kalrav_upload_file` (unauthenticated access) and lacks nonce/capability checks and file-type validation, saving uploads under `wp-content/plugins/kalrav-ai-agent/uploads/`, which is typically web-accessible—enabling RCE when PHP files are uploaded.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.