CVE-2026-54806 is an unauthenticated PHP object injection vulnerability in the WordPress plugin WP Activity Log (wp-security-audit-log) affecting versions up to and including 5.6.3.1. According to the provided content, the plugin records the HTTP User-Agent header during logged events without sanitization. That attacker-controlled value is later deserialized in the admin dashboard, causing instantiation of attacker-supplied PHP objects. The content further states that, when a suitable gadget chain is present—specifically the WP_HTML_Token gadget chain in WordPress 6.4.0 through 6.4.1—this deserialization flaw can be leveraged for blind pre-authentication remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit PoC for CVE-2026-54806, an unauthenticated PHP object injection vulnerability in the Melapress WP Activity Log WordPress plugin (wp-security-audit-log) <= 5.6.3.1. The main exploit file is cve-2026-54806.py, which uses requests/urllib3 to interact with a target WordPress site, detect WordPress and plugin presence, and inject a serialized PHP object through the User-Agent header on a request that causes a logged event, specifically a failed login. The exploit is blind: payload execution occurs later when an administrator loads the dashboard/widget path that deserializes the stored object. Capabilities exposed by the script include: a safe-ish vulnerability check mode (--check), arbitrary command execution (--command), reverse shell staging (--shell with attacker-supplied --lhost/--lport), and arbitrary file write (--write-file). The README states the gadget chain relies on WordPress core 6.4.0-6.4.1 using WP_HTML_Token, because its public properties survive sanitize_text_field() and fit the plugin’s storage constraints; WordPress 6.4.2 reportedly blocks the chain with __wakeup changes. The exploit therefore targets a specific plugin version range plus a narrow WordPress core version range for RCE reliability. Repository structure is simple and purposeful: the root contains documentation, dependency list, and the single Python exploit. The docker/ directory provides a reproducible vulnerable lab with docker-compose.yml, setup.sh to provision WordPress 6.4.1 and activate/configure WP Activity Log 5.6.3.1, and admin-bot.sh to repeatedly log in and visit /wp-admin/index.php so stored payloads automatically deserialize without manual admin interaction. This makes the repo both an exploit PoC and a self-contained demonstration environment. No evidence suggests this is fake or merely a detector. It is an operational exploit with built-in payload delivery options, though not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP object injection vulnerability in the WP Activity Log WordPress plugin that can lead to blind pre-auth remote code execution when combined with a WordPress gadget chain.
An unauthenticated PHP Object Injection vulnerability affecting the WordPress WP Activity Log plugin versions 5.6.3.1 and earlier. It is significant because it is remotely exploitable and has a critical CVSS 3.1 score of 9.8.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.