CVE-2026-15282 is an arbitrary file upload vulnerability in the Instant Appointment plugin for WordPress affecting all versions up to and including 1.2. The flaw is caused by missing file type validation in the insapp_upload_image_as_attachment function, which fails to properly restrict uploaded content to safe file types. As a result, an unauthenticated remote attacker can submit arbitrary files to the server. In WordPress deployments, this can permit upload of executable server-side content into a web-accessible location, creating a path to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-15282 affecting the Instant Appointment WordPress plugin <= 1.2. Structure is minimal: a README with vulnerability description and usage, one Python exploit script, and a requirements file. The main entry point is cve_2026_15282.py. The exploit is not just a detector: it performs end-to-end unauthenticated exploitation. It first probes for the plugin by requesting known plugin files under /wp-content/plugins/instant-appointment/ and optionally extracting the Stable tag version. It also attempts a POST to /wp-admin/admin-ajax.php with action=add_service_front as a secondary detection path. For exploitation, it crafts a PHP webshell, base64-encodes it, and passes it through a data://text/plain;base64,... URI in the image_url parameter while setting image_name to a .php filename. This abuses the vulnerable server-side file_get_contents() plus file_put_contents() flow to write attacker-controlled PHP into the WordPress uploads directory. After upload, the script checks likely shell locations under /wp-content/uploads/{year}/{month}/ and /wp-content/uploads/, then invokes the shell with the c parameter to run a command such as id and confirm RCE. The embedded payload executes arbitrary system commands via system($_GET["c"]." 2>&1"). The script supports mass scanning with threading, randomized user agents, optional debug/verbose output, optional persistence via --no-cleanup, and saving successful shell URLs to an output file. Overall purpose: automated discovery and exploitation of vulnerable WordPress sites running Instant Appointment, culminating in remote code execution through an uploaded PHP webshell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary file upload vulnerability in the Instant Appointment WordPress plugin caused by missing file type validation in the 'insapp_upload_image_as_attachment' function, affecting versions up to and including 1.2 and potentially enabling remote code execution.
A critical arbitrary file upload vulnerability in the WordPress Instant Appointment plugin caused by missing file type validation, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.