CVE-2026-7465 is a remote code execution vulnerability in Spectra Gutenberg Blocks – Website Builder for the Block Editor, formerly Ultimate Addons for Gutenberg, for WordPress through version 2.19.25. During Gutenberg block rendering, the plugin registers uagb/-prefixed block types using attributes derived from serialized post content. A Contributor-level or higher user can supply a render_callback attribute while registering a fake block type, then include a second block of that type so that sequential rendering invokes the attacker-selected PHP callback through call_user_func() in the same request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit repo containing one Python exploit script and a minimal README. The main file, CVE-2026-7465.py, targets CVE-2026-7465 in the Spectra Gutenberg Blocks WordPress plugin. It is an authenticated web exploit requiring Contributor-level or higher credentials. The script logs into WordPress, crafts malicious Gutenberg block content that abuses fake uagb/ block types and attacker-controlled render callbacks, and submits the payload in a draft post so that arbitrary PHP functions execute during rendering. The exploit supports multiple operational modes via CLI flags: proof-of-concept phpinfo execution, arbitrary PHP function invocation, file read via file_get_contents, file write via file_put_contents, command execution via shell_exec, verbose logging, and an interactive shell mode. Network interaction is limited to the target WordPress instance, primarily through /wp-login.php, /wp-json/wp/v2/posts, and /wp-admin/post-new.php. Overall, this is a real operational exploit rather than a detector, with practical post-exploitation capability but no evidence of framework integration or highly modular weaponization.
This repository is a self-contained local Docker lab and proof-of-concept for CVE-2026-7465 affecting the WordPress Spectra Gutenberg Blocks plugin (ultimate-addons-for-gutenberg). The repo contains 7 files: a README explaining the vulnerability and lab workflow, a docker-compose stack, two Dockerfiles that build vulnerable and patched WordPress images with Spectra 2.19.25 and 2.19.26 respectively, a Python PoC, and a shell script that seeds WordPress users and plugin activation. The main exploit logic is in poc/poc.py. It is a least-harm authenticated web exploit/verification script, not a destructive payload. It enforces localhost/loopback-only targeting, logs into WordPress using seeded Contributor credentials, scrapes /wp-admin/post-new.php for REST nonces, validates a nonce via /wp/v2/users/me, creates a draft post through /wp/v2/posts, and injects crafted Gutenberg block comments using a synthetic uagb/* block. The injected attributes include render_callback=maybe_serialize and a marker string. The script then fetches the post in edit context and compares raw versus rendered content. If the marker appears in rendered output, it concludes vulnerable behavior is present; otherwise it reports patched behavior. Finally, it deletes the temporary draft post. Exploit capability: demonstrate callback-control via attacker-controlled block attributes being passed into WP_Block_Type_Registry::register() in vulnerable Spectra versions. The PoC proves that a Contributor can influence block registration arguments, specifically render_callback, through post content. However, the repository intentionally avoids weaponization: no command execution, reverse shell, file upload, persistence, or privilege escalation payload is implemented. As provided, it is best classified as a proof-of-concept exploit lab rather than an operational exploit. Repository structure and purpose: docker-compose.yml orchestrates MariaDB, vulnerable/patched WordPress containers, and one-shot seed containers. scripts/seed-wordpress.sh installs WordPress if needed, activates the plugin, and creates the Contributor account used by the PoC. vuln/Dockerfile and patched/Dockerfile fetch exact plugin versions from downloads.wordpress.org. The README documents the root cause, vulnerable code path, patched diff, expected output, and safety constraints. Overall, the repository is designed for reproducible local validation and comparative testing of vulnerable versus patched behavior for CVE-2026-7465.
Repository contains a README and one Python exploit script. The README documents CVE-2026-7465 in Spectra Gutenberg Blocks <= 2.19.25, describing an authenticated Contributor+ arbitrary PHP function call / RCE path caused by unsafe registration of attacker-controlled block attributes into WP_Block_Type_Registry. The exploitation model is a two-block Gutenberg payload: the first malicious uagb/ block registers a fake block type with a chosen render_callback, and the second block with the same name triggers WordPress to call that callback with attacker-controlled arguments. The documented example uses wp_insert_user to create an administrator account. The main code file, poc.py, is a black-box HTTP exploit written in Python using requests. It performs reconnaissance against the target WordPress site, checks plugin presence via the Spectra plugin PHP path, checks REST API availability at /wp-json/, verifies wp-login.php accessibility, authenticates as a Contributor, creates a draft exploit post through HTTP interactions, triggers rendering via preview/frontend access, verifies success by attempting login as the newly created admin, and leaves artifacts for manual verification. The script is operational rather than a mere detector because it automates exploitation and post-exploitation verification. The attack vector is web-based and requires valid low-privileged WordPress credentials plus a vulnerable Spectra installation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity vulnerability affecting the Spectra Gutenberg Blocks (formerly Ultimate Addons for Gutenberg) WordPress plugin in versions through 2.19.25.
A remote code execution vulnerability in the Spectra Gutenberg Blocks – Website Builder for the Block Editor WordPress plugin affecting all versions up to and including 2.19.25, allowing authenticated attackers with Contributor-level access or higher to execute code on the server.
A high-severity remote code execution vulnerability in the Spectra Gutenberg Blocks WordPress plugin caused by passing user-controlled block attributes into block type registration, allowing a Contributor-level user to register an arbitrary PHP render_callback and execute it during block rendering.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.