CVE-2026-5524 is an unrestricted file upload vulnerability in the Divi Form Builder WordPress plugin affecting versions through 5.1.8. The do_image_upload() function incorporates the attacker-controlled acceptFileTypes POST value into the regular expression used for upload extension validation. An attacker can designate PHP-executable extensions not covered by the plugin's narrow .php-only protection, upload a server-executable payload, and invoke it over HTTP. Version 5.1.3 only partially addressed the flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone exploit toolkit for CVE-2026-5524 targeting Divi Form Builder <= 5.1.8 on WordPress. The main entry point is CVE-2026-5524.py, a Python mass-exploitation script that normalizes target URLs, crawls likely form pages to detect Divi Form Builder artifacts and extract fb_nonce values, then submits unauthenticated/weakly protected upload requests to /wp-admin/admin-ajax.php using action=de_fb_image_upload. It attempts multiple PHP-executable extensions such as .phtml, .phar, .php7, .php5, .php4, and .shtml to bypass extension filtering and the plugin’s upload protections, then verifies execution and optionally runs commands or opens an interactive shell. The exploit is operational rather than a simple PoC: it supports single-target and bulk targeting, threading, proxying, output logging, manual nonce override, aggressive bypass modes, optional null-byte/double-extension and path-traversal attempts, and post-exploitation command execution. The built-in default payload is a compact PHP webshell that executes base64-decoded commands from the x request parameter. Three auxiliary PHP payload files are included. bypass.phtml is a feature-rich obfuscated webshell/polyglot payload designed to survive WAF and handler restrictions; it supports multiple request parameters for command execution, file writing, reconnaissance, browsing directories, phpinfo exposure, helper installation, and reverse-shell initiation. htaccess_enable.phtml writes an .htaccess file to re-enable PHP handling for many extensions and auto-prepend bypass.phtml. user_ini.phtml writes .user.ini/user.ini files for PHP-FPM/FastCGI environments to auto-prepend itself and then exposes command execution and phpinfo. Overall purpose: automate exploitation of an arbitrary file upload vulnerability into reliable remote code execution across many WordPress targets, including fallback mechanisms for Apache and PHP-FPM environments where direct execution of uploaded files may initially fail.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file-upload remote-code-execution vulnerability affecting Divi Form Builder versions 5.1.8 and earlier.
An unauthenticated arbitrary file upload vulnerability in the Divi Form Builder WordPress plugin that can lead to remote code execution by bypassing file extension validation and uploading executable PHP files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.