The Friendly Functions for Welcart WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.2.5 due to missing or incorrect nonce validation on the plugin’s settings page. An attacker can craft a forged request that, when executed by an authenticated administrator (e.g., via clicking a link or visiting an attacker-controlled page while logged into wp-admin), results in unauthorized updates to the plugin’s configuration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a proof-of-concept (PoC) generator for CVE-2026-1208, a CSRF vulnerability in the WordPress plugin “Friendly Functions for Welcart” (<= 1.2.5) allowing settings updates without proper nonce validation. Structure/purpose: - exploit.py: Main PoC generator. Builds an HTML page containing a hidden form that POSTs to {TARGET}/wp-admin/admin.php?page=ffw-settings and auto-submits after a configurable delay. Supports custom key=value payload fields, writes output to a file (default csrf_payload.html), optionally opens the payload locally in a browser, and can host the payload via a built-in HTTP server bound to 0.0.0.0 on a configurable port (default 8888). - exploit.sh: Bash alternative that generates a similar HTML payload with fixed default fields and can host it using Python’s http.server. - USAGE.md/README.md: Documentation, exploitation steps, and a Nuclei template snippet for detection (fingerprinting plugin readme.txt and matching vulnerable stable tags). Also includes example ModSecurity/Nginx WAF rules. - requirements.txt: No external Python dependencies. - targets.txt.example: Example target list file (batch mode is mentioned as planned but not implemented). Exploit capabilities: - Generates a CSRF HTML payload that, when visited by an authenticated WordPress admin, triggers a forged POST to the plugin settings page. - Allows attacker-controlled setting fields (Python version supports arbitrary fields via --payloads; Bash version uses hardcoded example fields). - Provides optional local hosting of the payload for delivery. Notable constraints: - This is not an RCE or authentication bypass; it relies on victim admin session + user interaction (social engineering) and only changes plugin settings (integrity impact).
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.