The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all versions up to, and including, 1.0.26. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the 'maximum-num-years' attribute value is read directly from shortcode attributes and interpolated into a double-quoted HTML attribute without any escaping (no esc_attr(), htmlspecialchars(), or similar). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal local Linux privilege-escalation exploit consisting of one Bash script (`CVE-2026-3600.sh`) and a placeholder README. The script is not a scanner or detector; it actively attempts exploitation. Its purpose is to gain host root privileges from an unprivileged local account by abusing a cgroup v1 `release_agent` escape path from within a newly created user and network namespace. Operational flow: the script first verifies it is not already running as root and checks for required binaries (`unshare`, `mount`, `rmdir`, `ip`). It then creates a temporary shell payload under `/tmp/fragnesia.XXXXXX.sh`. That payload copies `/bin/bash` to `/tmp/.rootshell` and marks it setuid (`chmod 4755`), effectively creating a reusable root backdoor. Next, the exploit enters a new user+network namespace with `unshare --user --map-root-user --net bash`, brings up loopback, and attempts to mount a cgroup v1 memory controller at `/tmp/cg_escape`. It writes the payload path into `/tmp/cg_escape/release_agent`, creates a child cgroup, places the current process into it via `cgroup.procs`, enables `notify_on_release`, and removes the child cgroup to trigger the release handler. If successful, the host executes the payload as root and drops `/tmp/.rootshell`. The script then checks for that file and instructs the operator to run `/tmp/.rootshell -p` on the host. There are no network callbacks, remote C2 endpoints, or external downloads. All observables are local filesystem paths and namespace/cgroup interactions. The exploit is operational because it includes a working payload and exploitation logic, but it is not heavily modular or framework-based.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.