CVE-2026-49104 is an unauthenticated PHP Object Injection vulnerability affecting the WordPress plugin "Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms" in versions up to and including 1.2.1. The issue is classified as CWE-502 (Deserialization of Untrusted Data). Based on the available information, the plugin accepts attacker-controlled serialized PHP data in a way that permits object injection without authentication. No vulnerable function or code path is provided in the supplied content, but the vulnerability is remotely exploitable over the network with no privileges and no user interaction, per the published CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit project with 2 files: a primary script, CVE-2026-49104.py, and a minimal README. The Python script is the clear entry point and implements a multi-stage workflow for a claimed unauthenticated PHP object injection issue in a WordPress Keap/Infusionsoft integration plugin. Its overall purpose is to identify whether the plugin is installed, determine whether the installed version or code appears vulnerable, enumerate AJAX actions, search for potential POP-chain opportunities, and finally attempt exploitation using an operator-provided serialized PHP payload. The exploit logic is web-focused and targets WordPress plugin files directly over HTTP(S). It probes several likely plugin installation directories under /wp-content/plugins/, checks for cf7-infusionsoft.php and readme.txt, and then attempts to retrieve the plugin PHP file to parse version information and look for the unsafe maybe_unserialize pattern described in the header comments. The script exposes multiple CLI modes including detection-only, vulnerability-check-only, AJAX action discovery, AJAX action scanning, POP-chain discovery, and full exploitation. This indicates the repository is more than a simple detector: it includes reconnaissance and an exploitation path, though successful RCE depends on the target environment containing a usable PHP gadget chain. No external C2, hardcoded IPs, or third-party callback infrastructure are visible in the provided content. The main fingerprintable targets are WordPress plugin paths and likely the standard WordPress AJAX endpoint wp-admin/admin-ajax.php. Based on the visible code and CLI flow, the exploit is operational but not heavily weaponized: it supports real attack steps and payload delivery, but payload generation/customization appears to be left to the operator rather than embedded as a flexible framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.