The EventPrime plugin for WordPress is vulnerable in all versions up to and including 4.2.8.4 due to an unauthenticated, publicly accessible (nopriv-enabled) AJAX action registered for file upload (upload_file_media / ep_upload_file_media). The endpoint does not enforce authentication, authorization, or nonce verification (despite a nonce being created), allowing unauthenticated attackers to upload image files into the WordPress uploads directory and create corresponding Media Library attachments via the ep_upload_file_media endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python exploit for CVE-2026-1657 targeting the WordPress EventPrime Event Calendar Management plugin. It contains one executable script, CVE-2026-1657.py, and a minimal README with usage instructions. The script first fingerprints the target by requesting /wp-content/plugins/eventprime-event-calendar-management/readme.txt and parsing the 'Stable tag' value to determine the plugin version. It then compares the detected version against a hardcoded vulnerable threshold of 4.2.8.4. If the version appears vulnerable, or if version detection fails or the operator forces execution, it sends a multipart POST request to /wp-admin/admin-ajax.php with action=ep_upload_file_media and an attacker-supplied local file labeled as image/jpeg. On success, it parses the JSON response, prints the returned attachment ID, and predicts the uploaded file's public URL under /wp-content/uploads/YYYY/MM/. The exploit's main capability is unauthenticated file upload via a vulnerable AJAX endpoint; it does not include post-upload execution logic, shell delivery, or persistence mechanisms. Structurally, this is a simple operational PoC rather than a framework module: one script handles version checking, vulnerability decision logic, upload execution, and console output.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.