CVE-2026-2631 affects the Datalogics Ecommerce Delivery WordPress plugin prior to version 2.6.60. The plugin exposes an unauthenticated REST endpoint that allows any remote user to modify the WordPress option datalogics_token without verification. This token is later used as an authentication mechanism for a protected endpoint that permits arbitrary WordPress update_option() operations. By first setting datalogics_token and then invoking the protected functionality, an attacker can change site configuration such as enabling user registration and setting the default role to Administrator, effectively enabling administrative account creation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
update_option() capability after seeding the datalogics_token. This can lead to full site compromise, including enabling registration and setting the default role to Administrator, allowing attackers to obtain administrative access and subsequently execute administrative actions (e.g., plugin/theme modification, content tampering, persistence).If you can’t patch tonight, do this now.
users_can_register, default_role, and any plugin-specific token/secret options) and on unexpected creation of new administrator accounts.Patch, then assume compromise.
datalogics_token and subsequent arbitrary update_option() abuse.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone Python repository containing a single executable script, main.py, plus README and license. The script is an asynchronous mass exploitation/validation tool for alleged CVE-2026-2631 affecting a WordPress-exposed REST endpoint. It is not just a detector: it sends a POST request that attempts to modify the target's shop_secret/app secret value using action=resetStoreConfigrations and a supplied secret, making the check destructive. main.py uses aiohttp and asyncio to scan many targets concurrently, accepts a target list from a file, prompts the operator for confirmation, concurrency, and secret value, and disables SSL verification by default. For each target it normalizes the scheme, tries HTTPS first, then falls back to HTTP on connection or SSL errors, and marks a host vulnerable when the response is HTTP 200 and contains the regex-matched success message 'app secret key has been updated successfully' while excluding obvious error-page content. Positive hits are printed and saved to vuln_results.txt; non-vulnerable hosts are mostly suppressed except for aggregated error statistics. Repository structure is minimal and purpose-built for bulk validation of reachable WordPress targets/subdomains rather than full post-exploitation.
This repository is a small, single-purpose exploit project containing one Python exploit script (CVE-2026-2631.py), a README, and a license file. The code is a multithreaded operational exploit for CVE-2026-2631 affecting the WordPress plugin Datalogics Ecommerce Delivery before version 2.6.60. The exploit’s purpose is unauthenticated privilege escalation over the network. It targets WordPress sites by sending POST requests to the plugin REST endpoint /wp-json/gsf/v1/update-options. First, it invokes the resetStoreConfigrations action to overwrite the plugin’s shop_secret. It then uses createUpdateOption to set users_can_register=1 and default_role=administrator. After changing those options, it accesses /wp-login.php?action=register to confirm registration is enabled and attempts to create a new user with operator-supplied or default credentials. The net effect is creation of a new administrator account without prior authentication. Repository structure is straightforward: the Python file is the only code file and main entry point; README.md documents the vulnerability, workflow, usage, and mitigation; LICENSE contains restrictive redistribution terms. The script uses requests for HTTP, rich for terminal UI, threading and Queue for concurrent mass exploitation, and writes successful results to Login_admin.txt. It accepts a target list from list.txt by default, normalizes hostnames into URLs, processes targets in worker threads, and displays live status updates in a rich table. Notable fingerprintable artifacts include the vulnerable endpoint /wp-json/gsf/v1/update-options, the registration endpoint /wp-login.php?action=register, the action names resetStoreConfigrations and createUpdateOption, the modified option keys users_can_register and default_role, and local files list.txt and Login_admin.txt. This is clearly exploit code rather than a detector, and it includes a concrete payload path that changes configuration and provisions an admin account, making it operational rather than a simple proof of concept.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.