CVE-2026-7515 is an unauthenticated Local File Inclusion vulnerability in the BetterDocs Pro plugin for WordPress affecting versions up to and including 3.8.0. The flaw is exposed through the WordPress AJAX endpoint /wp-admin/admin-ajax.php using the action=load_more_docs_section request and the doc_style parameter. The available content indicates that attacker-controlled input in doc_style is used in a file include context without sufficient validation, enabling path traversal and inclusion of local files. A provided proof of concept uses doc_style=../../../../../../etc/passwd to demonstrate arbitrary local file disclosure. Where attacker-accessible PHP files exist on the server, the same flaw can be used to include and execute those .php files, resulting in PHP code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
doc_style values, and monitoring for requests targeting action=load_more_docs_section. Restrict or eliminate PHP file uploads and ensure uploaded content cannot be placed in locations that may later be included by the application. Harden filesystem permissions so the web server has minimal read access beyond required application paths.Patch, then assume compromise.
/wp-admin/admin-ajax.php with action=load_more_docs_section and suspicious doc_style traversal payloads, and investigate for signs of file disclosure or PHP-file inclusion attempts.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, focused exploit repo containing a README and one Python exploit script, cve_2026_7515_betterdocs_lfi.py. The script targets CVE-2026-7515 in BetterDocs Pro <= 3.8.0 on WordPress, described as an unauthenticated local file inclusion via the doc_style parameter that can potentially be escalated to RCE. The exploit is operational rather than a simple PoC: it includes CLI argument parsing, interactive mode, optional proxy support, SSL verification disabling, output logging, multi-target scanning support, threading, and automated nonce discovery. The nonce discovery logic spiders several likely public BetterDocs-related paths and also checks /wp-json/ for a usable nonce. The exploit then uses WordPress AJAX actions load_more_docs_section and load_more_docs against /wp-admin/admin-ajax.php to attempt traversal-based file inclusion. Built-in traversal payloads include multiple relative path and encoded traversal variants, improving reliability across filtering differences. The script also contains a curated list of sensitive file targets, including wp-config for WordPress secrets and database credentials, Linux system files, process metadata, and web server access logs. The inclusion of Apache and Nginx access logs, plus an explicit --rce option, strongly suggests support for LFI-to-RCE workflows such as log poisoning. Overall, the repository’s purpose is offensive exploitation of a vulnerable BetterDocs Pro installation to achieve unauthenticated arbitrary local file read and possibly remote code execution under favorable server conditions.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated local file inclusion vulnerability in BetterDocs Pro versions 3.8.0 and earlier, reachable via the WordPress admin-ajax endpoint using the load_more_docs_section action and the doc_style parameter.
A critical unauthenticated local file inclusion vulnerability in the BetterDocs Pro WordPress plugin that can allow inclusion and execution of arbitrary PHP files on the server, potentially leading to sensitive data access, access control bypass, or code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.