CVE-2026-3576 is an unauthenticated arbitrary file read vulnerability in the Planyo Online Reservation System plugin for WordPress affecting all versions up to and including 3.0. The issue resides in the plugin's directly accessible ulap.php AJAX proxy, which can be reached without WordPress bootstrapping or authentication. The vulnerable logic in send_http_post() validates only the host component of a user-supplied URL against an allowlist that includes localhost, but does not validate or restrict the URL scheme. As a result, an attacker can supply a file:// URL using localhost as the host, causing the allowlist check to succeed. The URL is then passed to functions that support local file access via the file wrapper, allowing the server to open and return arbitrary local files in the HTTP response. This effectively turns an SSRF-style proxy flaw into local file inclusion and arbitrary file disclosure, including sensitive application and system files such as WordPress configuration data and other server-resident files readable by the web server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python PoC for CVE-2026-3576 affecting the WordPress Planyo Online Reservation System plugin <= 3.0. The repo contains one executable code file (exploit.py), a README with usage and vulnerability context, a requirements file pinning requests, and a license. The exploit is not framework-based. The exploit has two main capabilities. First, it performs a pre-exploitation version check by requesting wp-content/plugins/planyo-online-reservation-system/readme.txt from the supplied WordPress base URL, parsing the changelog, and comparing the discovered version against a hardcoded vulnerable-version list. Second, it performs the actual exploit by sending a GET request to wp-content/plugins/planyo-online-reservation-system/ulap.php with the parameter ulap_url=file://localhost<user-supplied-file>. This abuses the SSRF behavior to access local files on the server and prints the response body directly to stdout. Operationally, the script is simple but functional: it accepts a target base URL, an optional file path (default /etc/passwd), and a flag to disable the version check. There is no post-exploitation, persistence, credential harvesting, or shell payload; the impact is arbitrary file disclosure only. Because it includes a working exploitation path and user-controlled target file selection, it is best classified as an OPERATIONAL PoC rather than mere detection. The attack vector is web/network-based and unauthenticated, assuming the vulnerable plugin path is reachable on the target WordPress installation.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary file read vulnerability in the Planyo Online Reservation System WordPress plugin (<= 3.0). The ulap.php endpoint is reachable without authentication and improperly validates user-supplied URLs, allowing file://localhost/ access and disclosure of local files such as /etc/passwd.
A local file inclusion (LFI) vulnerability affecting the WordPress Planyo plugin, demonstrated via a Metasploit auxiliary module that can retrieve arbitrary files such as /etc/passwd from vulnerable installations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.