CVE-2025-7441 is an unrestricted file upload vulnerability in the StoryChief plugin for WordPress affecting all versions up to and including 1.0.42. The flaw exists in the public REST API endpoint /wp-json/storychief/webhook, reportedly in the upload handling logic in includes/tools.php, where uploaded files are not subjected to sufficient filetype validation. Because the endpoint accepts attacker-controlled multipart POST data without adequate extension or MIME-type restrictions, an unauthenticated attacker can upload arbitrary files, including server-executable payloads such as a PHP web shell. The uploaded file is stored in a web-accessible location, allowing subsequent direct access over HTTP and making remote code execution possible on the affected WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a single Python PoC exploit (CVE-2025-7441.py), a README, and an MIT license. The PoC targets an unauthenticated arbitrary file upload / server-side remote file fetch issue in the StoryChief WordPress plugin (README cites version 1.0.42). The script builds a JSON webhook payload placing an attacker-chosen URL into `data.featured_image.data.sizes.full`, computes an HMAC-SHA256 over a JSON-escaped representation of the payload using an empty key, stores the hex digest in `meta.mac`, and POSTs it to `<site>/wp-json/storychief/webhook` (via Python requests or optional curl subprocess). After sending, it derives the expected WordPress uploads path based on the current year/month and the basename of the remote URL, then performs GET requests to `<site>/wp-content/uploads/YYYY/MM/<filename>` to confirm the file was persisted. Primary capability is forcing the target to download and publicly store attacker-controlled content; if the environment executes uploaded scripts from uploads, this can escalate to RCE, but the PoC itself focuses on upload verification rather than executing a command or shell.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-7441, a critical unauthenticated arbitrary file upload vulnerability in the StoryChief WordPress plugin (versions up to and including 1.0.42). The exploit is implemented in a single Python script (CVE-2025-7441.py) and is accompanied by a detailed README.md. The script constructs a specially crafted JSON payload that instructs the vulnerable endpoint (/wp-json/storychief/webhook) to fetch a remote file (defaulting to a PHP file hosted on GitHub) and save it in the WordPress uploads directory. The script then checks if the file was successfully uploaded by probing the expected uploads path. If the server allows execution of uploaded PHP files, this can result in remote code execution. The exploit is configurable via command-line arguments, allowing the user to specify the target site, the file to upload, verbosity, and delivery method (requests or curl). The repository is well-structured, with clear documentation and usage instructions, and is focused solely on demonstrating the exploitability of the vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.