The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept demonstrating cloud metadata theft via a DNS rebinding-to-SSRF scenario. It contains 5 files total: a LICENSE, README, and 3 Python scripts. The main components are: vulnerable_web_app.py, a Flask application exposing a /fetch endpoint that performs requests.get() on a user-supplied URL with no SSRF protections; exploit_dns_rebinding.py, which sends a request to the vulnerable app and instructs it to fetch the cloud metadata IAM credentials endpoint at 169.254.169.254/latest/meta-data/iam/security-credentials/; and dns_rebinding_server.py, which is only a stub and does not implement actual DNS server logic. The exploit capability is therefore credential theft from a cloud metadata service through a vulnerable fetch endpoint. Although the README frames this as DNS rebinding, the implemented exploit is simplified and directly supplies the metadata URL rather than performing real hostname rebinding or DNS response alternation. The repository's purpose is educational/demonstrative rather than operational: it models how a web app that re-fetches or resolves attacker-controlled URLs could be abused to access internal cloud metadata. No framework is used, no persistence or shell payload is included, and the code is best classified as a POC rather than a weaponized exploit.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.