CVE-2026-0926 is a Local File Inclusion vulnerability in the Prodigy Commerce plugin for WordPress affecting all versions up to and including 3.2.9. The issue is exposed via the 'parameters[template_name]' parameter, which is not properly restricted before being used in a PHP include/require-style context. An unauthenticated attacker can supply a crafted template path to force the application to include arbitrary local files. This can allow disclosure of sensitive files and, where attacker-controlled files can be placed on disk and then included, execution of arbitrary PHP code. The flaw maps to CWE-98, Improper Control of Filename for Include/Require Statement in PHP Program.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Single-file Python exploit targeting CVE-2026-0926 in the Prodigy Commerce WordPress plugin. The script first performs a GET request to the supplied base URL and uses a regex to extract a frontend-exposed nonce from JavaScript (matching var settings = {..."nonce":"..."}). It then sends a POST request to the WordPress AJAX endpoint /wp-admin/admin-ajax.php with action prodigy-render-my-account-widget and attacker-controlled parameters[template_name], enabling local file inclusion. The default demonstration reads /etc/passwd, but the file path is user-supplied via the -f/--file argument. Repository structure is minimal: one operational Python script using httpx, asyncio, argparse, regex, and urljoin. Its purpose is exploitation, not detection: it automates nonce retrieval and LFI triggering against vulnerable WordPress installations running the Prodigy Commerce plugin.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.