CVE-2026-6960 is an arbitrary file upload vulnerability in the BookingPress Pro plugin for WordPress affecting all versions up to and including 5.6. The flaw is caused by missing file type validation in the bookingpress_validate_submitted_booking_form_func function. When the vulnerable booking form is configured with a signature custom field, an unauthenticated remote attacker can submit crafted input that results in arbitrary files being uploaded to the server. Because the uploaded content may include executable server-side code, the vulnerability can lead to remote code execution on the affected WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC consisting of one Python script and one README. The main file, CVE-2026-6960.py, targets CVE-2026-6960 in BookingPress Pro <= 5.6 for WordPress. It is a real exploit, not a detector: it automates an unauthenticated arbitrary file upload chain that ends in remote code execution. The exploit logic follows the BookingPress booking workflow rather than attempting a direct upload. First, it requests a public booking page and scrapes a WordPress _wpnonce from the HTML/JS. Second, it POSTs to /wp-admin/admin-ajax.php with action=bookingpress_fetch_timeslot_data to obtain a transient key. Third, it POSTs again with action=bookingpress_pre_booking_verify_details to obtain a verification token. Finally, it submits the vulnerable booking action bookingpress_book_appointment_booking with a crafted signature custom field containing a data URI of the form data:image/{ext};base64,{payload}. By injecting php as the MIME subtype, the plugin derives a .php extension from attacker-controlled input and writes the decoded content into /wp-content/uploads/bookingpress/. The embedded payload is a simple PHP web shell using shell_exec on the cmd query parameter. After upload, the script verifies exploitation by requesting the uploaded file and executing a test command. This makes the exploit operational rather than a bare proof of concept. Repository structure is minimal: README.md documents the vulnerability, prerequisites, attack flow, usage, and remediation; the Python script contains the full exploit chain and CLI handling. No external framework is used. The exploit is dependent on specific target conditions: a publicly accessible BookingPress form page, at least one active service, and a signature-type custom field configured by the administrator. Without that signature field, the described vector does not work.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.