CVE-2026-6440 is a cross-site request forgery vulnerability in the GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress affecting versions up to and including 1.1.8. The issue is caused by missing nonce verification in the reset_credential() function, which services the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. Although the function checks that the caller has the manage_options capability, it does not validate a CSRF token. As a result, an attacker can cause an authenticated administrator to unknowingly submit a forged request that resets the plugin’s stored Google Meet API credentials and OAuth tokens, disabling the site’s Google Meet integration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file Python exploit targeting CVE-2026-6440 in the WordPress WC Designer Pro plugin/component. The script is an unauthenticated file-upload exploit intended to achieve RCE by uploading a PHP shell to multiple target sites. Repository structure is minimal: one Python entry-point script with console UI, target loading, multithreaded execution, and result logging. The code uses requests/urllib3 for HTTP interactions and rich for terminal presentation. It prompts the operator for a target list and thread count, reads URLs from a file, splits them across worker threads, and calls an internal send_exploit routine for each target. Successful compromises are written to success_results.txt and uploaded shell locations to uploaded_shells.txt. The visible code clearly indicates offensive exploitation rather than mere detection, though the truncated content prevents extraction of the exact vulnerable upload endpoint path used against the WordPress targets.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.