CVE-2026-40791 is an unauthenticated cross-site scripting (XSS) vulnerability affecting WP Time Slots Booking Form versions 1.2.46 and earlier. Based on the provided content, the flaw allows attacker-controlled script to be injected and executed in a victim's browser without requiring authentication. Specific vulnerable parameters or functions were not provided in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small, focused PoC for CVE-2026-40791, an unauthenticated stored XSS in the WordPress WP Time Slots Booking Form plugin affecting versions up to 1.2.46. The exploit abuses the plugin's appointment parser, which splits the submitted booking string on literal spaces and stores the second token as the slot value. By inserting a tab between an SVG tag name and its onload attribute, the attacker preserves the payload through the parser while still producing executable HTML when the stored booking is rendered in the administrator Booking Orders page. Structure: README.md documents the vulnerability, exploitation flow, impact, and patch details. poc/reproduce.ps1 and poc/reproduce.sh are the main exploit files; both submit an unauthenticated POST request to a public WordPress booking page using parameters such as cp_tslotsbooking_pform_process=1, cp_tslotsbooking_id, and fieldname1_1 containing the crafted slot payload. The PowerShell version supports operator-supplied Target, PageId, FormId, Date, TimePrefix, and PayloadJs values; the Bash version supports target URL, page ID, optional form ID, and environment-variable overrides for payload components. lab/render-check.html and lab/validate-render.ps1 are local validation artifacts that demonstrate the parser/browser behavior without a full WordPress installation. Main capability: the PoC stores attacker-controlled JavaScript in booking data and relies on later admin interaction to trigger execution. The default payload is a simple alert, but the exploit is readily adaptable to arbitrary JavaScript, making it useful for admin-session abuse such as reading same-origin admin pages, extracting nonces, and sending authenticated administrative requests. This is a real exploit PoC rather than a detector, and its maturity is operational because it includes working submission scripts with customizable payload content.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.