CVE-2026-1306 is an arbitrary file upload vulnerability in the WordPress midi-Synth plugin affecting all versions up to and including 1.1.0. The flaw is caused by missing server-side file type and file extension validation in the plugin's 'export' AJAX action exposed through /wp-admin/admin-ajax.php. An attacker can supply a crafted file name and attacker-controlled content, causing the plugin to write an arbitrary file into the plugin's web-accessible sound directory under /wp-content/plugins/midi-synth/sound/. Although the export workflow uses a nonce, the nonce is exposed in frontend JavaScript, making it trivially obtainable by unauthenticated users. As a result, unauthenticated attackers can abuse the export action to place arbitrary files on the server, including files that may enable remote code execution depending on server configuration and executable file handling.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, focused exploit PoC containing one Python script and one README. The main file, 'CVE-2026-1306 midi.py', is a multithreaded list-runner for exploiting CVE-2026-1306 in the WordPress midi-Synth plugin. Its workflow is: normalize each target to an HTTPS base URL, probe likely frontend paths for a page containing the [midiSynth] shortcode, extract the JavaScript variable 'midiSynth_nonce' via regex, submit a POST request to '/wp-admin/admin-ajax.php' with 'action=export', and supply a Base64-encoded PHP payload as 'fileMidi' using the filename 'murrez.php'. The exploit relies on the vulnerable behavior described in the README: even when API key validation fails, the uploaded file may remain in '/wp-content/plugins/midi-synth/sound/'. The script then requests the expected shell URL to confirm successful deployment. The payload is not just a marker; it is a functional PHP uploader web shell that accepts uploaded files through a form and writes them to disk. Because the payload is hardcoded and the exploit automates exploitation across multiple targets with 20 threads, this is best classified as OPERATIONAL rather than a simple detection script or a pure PoC. The repository does not appear to belong to a common exploit framework such as Metasploit or Nuclei. Repository structure is minimal: the Python script contains all exploit logic, including nonce extraction, POST construction, verification, concurrency, and result logging; the README explains the vulnerability, affected versions (reported as <= 1.1.0), usage, and defensive guidance. No additional modules, obfuscation, or framework scaffolding are present.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical vulnerability identified as CVE-2026-1306 affecting the WordPress midi-synth plugin, demonstrated via a Nuclei template that triggers an export action through admin-ajax.php and retrieves a generated file from the plugin sound directory, indicating arbitrary file creation/export behavior.
An arbitrary file upload vulnerability in the WordPress midi-Synth plugin (<= 1.1.0) caused by missing file type validation, which can enable unauthenticated remote code execution.
An arbitrary file upload vulnerability in the WordPress midi-Synth plugin (<= 1.1.0) via the 'export' AJAX action due to missing file type/extension validation; can enable unauthenticated file upload and potentially remote code execution because a required nonce is exposed in frontend JavaScript.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.