CVE-2026-5229 is a critical authentication bypass vulnerability in the Form Notify plugin for WordPress, affecting versions up to and including 1.1.10. The flaw is in the plugin’s LINE OAuth login flow, where the callback logic determines which WordPress account to authenticate based on an email value that can be sourced from client-controlled state. Specifically, when the LINE provider does not return an email address, the plugin falls back to a cookie value and uses that email for WordPress user lookup without verifying that the authenticated LINE account is actually bound to that email identity. As a result, an attacker can complete a legitimate LINE OAuth flow with their own LINE account while supplying a victim’s email address through the fallback mechanism, causing the plugin to establish a WordPress session as the victim user. The issue can lead to arbitrary account takeover, including administrator accounts, on sites where the vulnerable plugin and LINE OAuth login are enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Python exploit/scanner and a README describing CVE-2026-5229, an unauthenticated authentication bypass in the WordPress Form Notify plugin’s LINE OAuth integration. The exploit targets two vulnerable paths described in comments and documentation: Path A for <= 1.1.08 abuses the plugin’s fallback to the attacker-controlled form_notify_line_email cookie when LINE does not return an email; Path B for <= 1.1.10 abuses account resolution by email only, with no linkage check between the LINE identity and the WordPress account. The intended outcome is account takeover of arbitrary users, including administrators. The main script, CVE-2026-5229.py, is a threaded bulk scanner/exploit tool written in Python using requests, argparse, regex, and concurrent futures. It includes helper routines to discover likely victim accounts by querying WordPress REST API endpoints such as /wp-json/wp/v2/users and by scraping public pages like lost-password, contact, about, author pages, and a plugin-related REST path for exposed email addresses. The visible code shows single-target and bulk-target modes, progress reporting, output logging, and result filtering for successful authentication states such as AUTH_SUCCESS or REDIRECT_ADMIN. Although the middle of the script is truncated, the repository clearly presents operational exploit logic rather than a pure detector. Fingerprintable targets in the code are primarily WordPress web endpoints used for user enumeration and plugin interaction. The README further documents the vulnerable REST namespace form-notify/v1 and callback route, the cookie name form_notify_line_email, and the transient/session state key prefix form_notify_line_state_. The repository is small and purpose-built: one Python exploit file and one markdown documentation file. It is not part of a known exploit framework. Overall, this is an operational web exploit/scanner for mass testing and exploitation of vulnerable Form Notify plugin deployments via LINE OAuth authentication bypass.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability in the Form Notify WordPress plugin that allows unauthenticated attackers to log in as arbitrary users, including administrators, by abusing LINE OAuth flow and a user-controlled cookie.
An authentication bypass/account takeover vulnerability in the Form Notify WordPress plugin's LINE OAuth integration, caused by trusting a client-controlled cookie as the fallback email for user identity binding.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.