CVE-2026-5118 is a critical privilege escalation vulnerability in the Divi Form Builder plugin for WordPress affecting versions up to and including 5.1.2. The flaw is in the plugin's user registration handling logic, which accepts a user-controlled role parameter from POST data and fails to validate it against the form's configured default user role. Because the server trusts the attacker-supplied role value instead of enforcing the role defined in the registration form settings, an unauthenticated attacker can tamper with a registration request and cause the application to create a new account with elevated privileges, including administrator. The issue is remotely exploitable with low complexity and does not require prior access or user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains two standalone Python tools and a GitHub Actions Conda/lint/test workflow. `CVE-2026-5118.py` is the primary operational tool: a threaded, proxy-capable mass scanner/exploit for an alleged unauthenticated privilege-escalation flaw in Divi Form Builder. Its documented chain performs target reachability checks with HTTP fallback, plugin/version identification through `readme.txt`, form discovery using REST, sitemap, crawling, and probing methods, extraction of a `de_fb_obj` nonce, submission of a WordPress AJAX role-injection registration request, login verification, and JSONL/success-file recording of credentials and cookies. It disables TLS certificate verification and uses randomized browser User-Agent strings. The embedded default credentials make the payload basic and hardcoded, supporting an OPERATIONAL rather than weaponized maturity assessment. `CVE-SCAN.py` is a separate passive-oriented version scanner. It loads target URLs from a file, detects WordPress and Divi Form Builder indicators from page content, optionally queries `/wp-json/wp/v2/plugins`, compares discovered versions against affected versions through 5.1.2 and fixed versions from 5.1.3, and writes categorized target lists. `README.md` presents the repository as defensive research, but the main Python file contains exploit behavior beyond detection, namely account creation/privilege escalation and credential-cookie collection. The supplied content does not independently validate the CVE assignment or vulnerability claim; the assessment reflects the implemented and documented code behavior.
This repository contains a Python exploit for CVE-2026-5118 targeting the WordPress plugin Divi Form Builder <= 5.1.2. Despite the README mentioning both a single-target exploit and a mass scanner, the repository as provided contains one code file, CVE-2026-5118.py, plus documentation. The Python script is a threaded mass scanner/exploit that automates the full attack chain against multiple targets. Core capability: unauthenticated privilege escalation to full WordPress administrator by abusing role injection in the plugin’s registration flow. The exploit logic, as described in the script header and README, performs: (1) target reachability checks with HTTPS-first behavior and HTTP fallback, (2) plugin detection via readme.txt version checks, (3) form discovery using REST/sitemap/crawl/probing techniques to locate any Divi Form Builder form, (4) extraction of a shared nonce from the de_fb_obj JavaScript object, (5) submission of a forged POST request to /wp-admin/admin-ajax.php using action=de_fb_ajax_submit_ajax_handler with form_type=register and role=administrator, and (6) login verification against /wp-login.php to confirm the created admin account. The exploit is operational rather than a simple PoC because it includes end-to-end automation, credential customization, login verification, multithreading, proxy support, retry logic, progress reporting, and result logging. It is not merely a detector; its intended outcome is creation of attacker-controlled administrator accounts. Default credentials embedded in the script are DEFAULT_USER=beelze_admin, DEFAULT_NEW_PASS=Beelze123!!@#!, and DEFAULT_EMAIL=beelze@exploit.lab. Repository structure is minimal: one Python script and one README. The Python file imports requests, urllib3, rich, threading, queue, and related standard libraries. It defines session-building helpers, URL normalization, HTTP fallback, logging/progress utilities, and a main threaded worker flow. The README provides vulnerability background, root-cause explanation, attack chain, usage examples, and expected output paths. Overall, the repository’s purpose is mass exploitation of vulnerable WordPress sites running the affected Divi Form Builder plugin version.
Repository contains a README and a single Python exploit script. The README documents CVE-2026-5118 affecting the WordPress Divi Form Builder plugin <= 5.1.2, describing an unauthenticated privilege-escalation flaw caused by unsafe acceptance of a user-supplied role during registration. The exploit.py script is the operational component: it uses requests and concurrent.futures to scan one or many WordPress targets, discover any Divi Form Builder-enabled page, and then abuse the shared AJAX submission handler to create a new privileged account. The script structure is centered around a DFBExploit class. It initializes an HTTP session with certificate verification disabled and a browser-like User-Agent. Discovery logic in find_form() probes a list of common registration/contact-style paths, then queries WordPress REST API endpoints for pages/posts and several likely custom post types, and finally falls back to sitemap, robots.txt, and homepage link crawling. Page inspection looks for Divi Form Builder indicators such as fb_nonce, de_fb_obj, divi-form-builder, and the AJAX handler string. This indicates the exploit is designed to work even when no obvious registration page exists, by weaponizing any exposed DFB form. Based on the README and visible code, the main exploit capability is unauthenticated administrator account creation via crafted POST data that overrides form_type to a registration flow and injects role=administrator. The script supports custom username, password, and email values, single-target exploitation, threaded mass scanning, optional verbose output, timeout control, and writing successful results to a file. It includes a permission confirmation prompt unless --no-confirm is used. Overall, this is a real exploit rather than a detector: it performs active exploitation and attempts to verify successful account creation.
Repository contains a single Python 2 exploit script and a README. The script is a multithreaded mass-exploitation tool targeting CVE-2026-5118 in Divi Form Builder/related Divi registration forms on WordPress. Its workflow is: normalize each supplied target URL, fetch the target page, extract an fb_nonce using several regex patterns, then submit a crafted multipart/form-data POST to /wp-admin/admin-ajax.php with action de_fb_ajax_submit_ajax_handler and role=administrator. If the response contains generic success indicators, it treats the target as compromised and writes target/wp-admin/ plus the hardcoded credentials to results.txt. The exploit supports bulk target lists, 20 concurrent threads by default, and uses hardcoded account details (Attacker / Attacker@123#+ / mail@admin.com). This is not merely a detector: it actively attempts unauthorized administrator account creation. The repository structure is minimal: CVE-2026-5118.py is the operational exploit entry point, while README.md documents setup, usage, expected output, and mitigation guidance.
Repository contains a single Python exploit script and a minimal README. The main file, CVE-2026-5118.py, is a standalone batch exploit targeting WordPress sites running Divi Form Builder vulnerable to CVE-2026-5118, described in the script as an unauthenticated privilege-escalation issue via role injection. The script is not part of a larger exploit framework. Operational flow: it normalizes target URLs, randomizes HTTP headers/user agents, optionally uses a proxy, and creates a requests session with TLS verification disabled. It then performs detection by fetching the site homepage and looking for plugin-specific form fields, probing the REST endpoint /wp-json/divi-form-builder/v1 for plugin presence/version, posting to /wp-admin/admin-ajax.php with action=de_fb_ajax_submit_ajax_handler and form_type=register to verify the AJAX handler, and checking plugin readme files under wp-content/plugins for version strings. If a version is found and is >= 5.1.3, the script considers the target patched. Although the middle of the file is truncated in the provided content, the visible class structure and run path indicate the exploit extracts form parameters such as nonce/form metadata, then submits a crafted registration request intended to inject an elevated role and create a privileged account. The script accepts attacker-supplied username, password, and email values, supports single-target or list-based batch mode, uses multithreading via ThreadPoolExecutor, tracks progress, and writes consolidated results to an output file. Overall purpose: automated mass exploitation of a vulnerable WordPress plugin to gain administrative access by creating unauthorized high-privilege users. Main capabilities are target detection, version fingerprinting, exploitation, and batch reporting.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A comparable unauthenticated privilege escalation vulnerability in Divi Form Builder mentioned for background context.
A privilege escalation vulnerability in the Divi Form Builder plugin for WordPress that allows unauthenticated attackers to create administrator accounts by manipulating the user registration role parameter.
An unauthenticated privilege escalation vulnerability in the Divi Form Builder WordPress plugin caused by missing server-side validation of the submitted role parameter during user registration, allowing attackers to create administrator accounts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.