CVE-2026-7459 affects the Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress in all versions up to and including 5.26.0. The vulnerability is an authorization flaw in the REST event reaction endpoints implemented by react_to_event() and unreact_to_event(). These endpoints use get_items_permissions_check() as their permission_callback, which only verifies that the requester is authenticated, but does not enforce the per-logger capability restrictions normally applied by Log_Query. Because of this mismatch, a low-privilege authenticated user such as a Subscriber can access the full context of Simple History events by sending a POST request to /wp-json/simple-history/v1/events/<id>/react with the _fields=context query parameter. This can expose sensitive event data, including SimpleUserLogger entries containing the full password-reset email body and reset URL with reset key for arbitrary users. An attacker can trigger a password reset for an administrator through the standard lost-password workflow, enumerate recent event IDs via the vulnerable reaction endpoint, retrieve the resulting user_requested_password_reset_link event, extract the reset key from context.message, and then complete the password reset to take over the target account. The issue is only exploitable when the plugin's experimental features option, simple_history_experimental_features_enabled, has been enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script and a minimal README. The main file, CVE-2026-7459.py, is a standalone operational exploit for a missing-authorization issue in the WordPress Simple History plugin. The script uses requests.Session for authenticated interaction with a target WordPress site and exposes multiple modes through argparse: event enumeration, password-reset triggering, reading a specific event context, and a full end-to-end account takeover workflow. Visible functions show login to /wp-login.php, a feature check against /wp-json/simple-history/v1/events/1/react, and audit log enumeration through /wp-json/simple-history/v1/events. Based on the script description and CLI options, the intended flow is: authenticate as a Subscriber, verify the vulnerable REST behavior, enumerate or directly access audit events, recover password reset material from logged event context, and reset the victim's password. This is not merely a detector; it is an exploit automating authenticated abuse of WordPress REST endpoints to achieve account takeover.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.