CVE-2026-3462 affects the Frisbii Pay plugin for WordPress. In all versions up to and including 1.8.9, the plugin's 'upload_csv' and 'process_batch' functions lack proper capability checks. As a result, authenticated users with Subscriber-level access or higher can invoke these functions to upload arbitrary CSV data. The vulnerable functionality can then be abused to overwrite WooCommerce payment tokens as well as postmeta and order meta records, resulting in unauthorized modification of application data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit generator, not tied to a major exploitation framework. It contains two identical Python scripts (`poc.py` and `cve_2026_34621_advanced/cve_2026_34621_advanced.py`) plus top-level and subdirectory README files. The main purpose is to generate a malicious PDF that embeds JavaScript intended to exploit CVE-2026-34621 in Adobe Acrobat/Reader via prototype pollution leading to sandbox escape and arbitrary command execution. Repository structure is simple: the root README gives a short description; the detailed README documents installation, CLI options, usage examples, affected versions, and attack flow; the Python script implements the generator. The code imports standard Python libraries plus optional `PyPDF2` for lure-PDF merging. Visible code sections show helper utilities for polymorphism/randomization, a multi-level JavaScript obfuscator, payload generation flow, PDF building, and report generation. The script accepts command-line options for output file, Windows/macOS commands, stage URL, persistence, obfuscation level, delay, hostname keying, lure PDF path, trigger type, and report suppression. Main exploit capabilities described by the code and documentation include: generating PDF-embedded JavaScript, OS auto-detection, Windows/macOS-specific execution paths, optional staged payload download from a remote URL, optional persistence installation, optional lure PDF merging, multiple trigger vectors (`openaction`, `pageopen`, `doclevel`), and HTML/TXT/JSON reporting. The exploit is operational rather than a mere PoC because it provides configurable payload delivery and persistence features, though it is still a standalone generator rather than a framework-integrated weaponized module. Fingerprintable observables are mostly example endpoints and execution artifacts from the README: staged payload URLs (`http://10.0.0.5/shell.ps1`, `http://192.168.1.100/payload.exe`, `http://10.0.0.5/mac_payload.sh`), reverse-shell endpoint `10.0.0.5:4444`, macOS application paths, `/bin/sh`, Windows execution components (`cmd.exe`, PowerShell, WScript.Shell), and persistence locations such as the Windows Run registry key and macOS LaunchAgents directory. Because the Python source was truncated in the provided content, some exact embedded strings from the payload generator cannot be fully verified from code alone, but the repository clearly implements an exploit generator rather than a detector or benign demo.
Repository contains a Python-based exploit generator rather than a simple detector. There are 4 files total: a top-level README, a subdirectory README, and two identical Python scripts (poc.py and cve_2026_34621_advanced/cve_2026_34621_advanced.py, both ~35 KB). The Python script is the main entry point and presents itself as an 'Advanced Cross-Platform Exploit Generator' for CVE-2026-34621 affecting Adobe Acrobat/Reader. The script structure, based on visible code and documentation, includes: utility helpers for randomization/polymorphism; a JavaScript obfuscator supporting multiple levels including string-to-charcode conversion, junk/dead-code insertion, and base64 wrapping; a payload generator that builds OS-aware JavaScript for Windows/macOS execution; a PDF generator that embeds the JavaScript into a PDF with selectable trigger vectors; optional lure PDF merging using PyPDF2; and a report generator that emits HTML/TXT/JSON artifacts describing the generated payload/configuration. Primary exploit capability is malicious PDF generation for file-based delivery. The generated PDF is intended to exploit Adobe JavaScript prototype pollution and claimed sandbox escape to reach privileged APIs and execute attacker-controlled system commands. The repository advertises Windows execution through cmd.exe, PowerShell, and WScript.Shell, and macOS execution through Terminal.app or osascript. It also supports optional staged payload retrieval from a remote URL, execution delay, hostname/environment keying, persistence installation, and obfuscation to hinder analysis. Fingerprintable observables are mostly examples in documentation rather than hardcoded C2: sample staging URLs (http://10.0.0.5/shell.ps1, http://192.168.1.100/payload.exe, http://10.0.0.5/mac_payload.sh), a reverse-shell callback endpoint (10.0.0.5:4444), example local file paths for Calculator.app and lure PDFs, and claimed persistence locations including the Windows Run registry key and macOS LaunchAgents directory. No evidence in the provided excerpt suggests a fixed attacker-controlled infrastructure embedded in the code itself; payload endpoints appear operator-supplied via CLI options such as --stage. Overall, this is an operational exploit builder with configurable payloads and delivery options, not merely a proof-of-concept or scanner.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.