CVE-2026-2020 is a PHP Object Injection vulnerability in the JS Archive List plugin for WordPress affecting all versions up to and including 6.1.7. The plugin deserializes untrusted user-controlled data supplied via the shortcode attribute/parameter 'included', enabling authenticated attackers with Contributor-level (or higher) privileges to inject arbitrary PHP objects. The vulnerable condition is the unsafe deserialization of attacker-controlled input originating from shortcode processing. The plugin itself is not known to include a usable POP (property-oriented programming) chain; however, if a POP chain is available from other installed plugins/themes in the same WordPress environment, exploitation can be escalated to more severe outcomes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small 4-file proof-of-concept repository demonstrating SSRF caused by URL parser differential behavior between Python urllib.parse and requests. The repository contains two Python files: vulnerable_service.py, a minimal Flask app exposing /fetch on port 5000, and exploit_ssrf_parser_diff.py, which sends a crafted URL parameter to exploit the flaw. The vulnerable service validates the supplied URL using urllib.parse.urlparse() and only permits hostnames localhost or 127.0.0.1, but then fetches the same URL with requests.get(). The exploit abuses userinfo syntax with '@' in the payload http://localhost@evil.com:5000/secret so the validation logic treats localhost as acceptable while the HTTP client connects to evil.com. This is a real exploit POC rather than a detection script: it demonstrates whitelist bypass and server-side outbound request redirection, potentially enabling access to internal services or metadata endpoints if adapted. Repository structure is straightforward: LICENSE, README.md with vulnerability explanation and usage steps, the vulnerable demo service, and the exploit script.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.