CVE-2026-12416 is a critical account takeover vulnerability in the Invoice Generator plugin for WordPress affecting all versions up to and including 1.0.0. The flaw is in the plugin’s password reset logic, specifically the pravel_invoice_change_password() function, which is exposed through a wp_ajax_nopriv AJAX handler and therefore reachable without authentication. The function does not perform nonce verification or authorization checks before processing a password change. It also validates the attacker-supplied reset_activation_code POST parameter against the target user’s stored forgot_email user meta using a loose equality comparison. For users who have never initiated a forgot-password flow, that stored value may be empty, allowing the comparison to succeed when the attacker omits the reset code and the check effectively becomes '' == ''. An unauthenticated attacker can send a crafted POST request to /wp-admin/admin-ajax.php with action=pravel_invoice_change_password, specify an arbitrary target via reset_user_id, and set new_password_custom to an attacker-chosen password, thereby resetting the victim’s password without authorization.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/wp-admin/admin-ajax.php when action=pravel_invoice_change_password. Monitor for exploitation attempts, especially POST requests containing action=pravel_invoice_change_password, reset_user_id, and new_password_custom, and investigate successful responses such as 'Password has been changed successfully'. Review WordPress accounts for unauthorized password changes, newly created privileged users, and signs of post-compromise activity.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python exploit/scanner for two WordPress plugin vulnerabilities: CVE-2026-12416 in Invoice Generator <= 1.0.0 and CVE-2026-12417 in SignUp & SignIn <= 1.0.0. The repository contains one main code file, a README describing the vulnerabilities and workflow, and a custom license. The Python script is the operational entry point and implements concurrent mass scanning against a list of target WordPress sites. Core exploit capability: the script abuses unauthenticated WordPress AJAX handlers exposed through /wp-admin/admin-ajax.php using the actions pravel_change_password and pravel_invoice_change_password. It submits reset_user_id, an attacker-chosen new_password_custom value, and an empty reset_activation_code to trigger arbitrary password resets for guessed user IDs. The hardcoded replacement password is Nxploited@123KSa. Operational flow: for each target, the script first probes likely user IDs (1 and 2), then optionally expands to IDs 3 through 20 if needed. After a successful reset indication (matching the success string '"activation":true'), it attempts to determine the corresponding username using WordPress REST API endpoints and author enumeration techniques, then logs in through /wp-login.php. It confirms administrator access by requesting /wp-admin/users.php and checking whether the session has sufficient privileges. Confirmed admin compromises are written to scan_results/pravel_admin_success.txt. Repository structure is simple and purpose-built for exploitation rather than detection. It includes threading support via ThreadPoolExecutor for mass scanning, randomized User-Agent selection, timeout tuning, console output formatting with rich, and synchronized file/result handling. This is a real exploit with post-exploitation validation logic, not merely a detector or README-only proof of concept.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated account takeover vulnerability in the WordPress Invoice Generator plugin affecting all versions up to and including 1.0.0, caused by weak password reset validation, missing nonce verification, missing authorization checks, and a loose equality comparison that allows attackers to reset arbitrary users' passwords, including administrators.
A critical account takeover vulnerability in the Invoice Generator plugin for WordPress caused by a weak password reset mechanism that allows unauthenticated attackers to reset arbitrary user passwords and fully compromise the site.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.