CVE-2026-8832 is a remote code execution vulnerability in the WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress affecting versions up to and including 2.3.5. The issue stems from the 'wpcode' custom post type being registered in wpcode_register_post_type() without a custom capability_type or other restrictive capability mapping. As a result, WordPress falls back to standard post capabilities for creation and publishing flows, including XML-RPC. An authenticated attacker with author-level privileges or higher can use the XML-RPC wp.newPost method to create and publish a wpcode snippet containing executable PHP. That PHP is later executed server-side through eval() in the plugin's run_eval() function when the snippet is rendered via the [wpcode] shortcode.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script and a README. The script, wpcode_rce_tester.py, is an interactive authenticated RCE tool targeting WPCode Lite (Insert Headers and Footers) <= 2.3.5 on WordPress. It manually constructs XML-RPC requests using Python's xml.etree.ElementTree and sends them with requests. The exploit chain described in both the README and script is: fingerprint the target for WPCode/XML-RPC exposure, authenticate with valid Author-or-higher WordPress credentials, create a malicious wpcode custom post via the XML-RPC method wp.newPost, then trigger execution through a [wpcode id=X] shortcode. The script also tracks created post IDs and offers cleanup of artifacts afterward. Capabilities go beyond simple detection: it is a working exploitation utility with multiple built-in PHP payloads, including system/user info disclosure, phpinfo, WordPress configuration reading, recursive file listing, a GET-parameter interactive PHP shell, a browser-based POST shell, a benign proof-of-concept echo payload, and custom operator-supplied PHP. This makes it an operational exploit rather than a mere scanner. The primary attack vector is web/network-based against the WordPress XML-RPC endpoint, but it requires authenticated access and a vulnerable plugin configuration. No evidence suggests it belongs to a larger exploit framework; it is a standalone Python PoC/exploitation tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.