Vulnerability Title
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a standalone Python-based WordPress security assessment tool centered on CVE-2026-9271, a stored XSS vulnerability in the KeepInMind / KeepInMind Dashboard Notes plugin. The repository is small and simple: one large Python script (`CVE-2026-9271.py`), a README, a requirements file, and a license. The Python script is the clear entry point and appears to implement the full workflow rather than relying on an external exploit framework. Main capabilities: the script detects whether the KeepInMind plugin is installed, identifies vulnerable version ranges, optionally authenticates to WordPress as a Contributor+ user, injects a stored XSS payload through the plugin’s REST API, verifies whether the payload renders, and optionally cleans up injected notes. It also supports bulk scanning with concurrency, SQLite-backed result storage, report generation, logging, and an optional local web/capture server. The included `CredentialCaptureHandler` shows explicit support for receiving POSTed credentials at `/capture` and listing them at `/captured`, indicating the tool goes beyond pure detection and can support controlled credential-capture simulations once XSS executes in an admin browser. From a defensive-analysis perspective, this is not merely a detector: it contains exploit logic for authenticated stored XSS assessment and optional post-XSS credential collection infrastructure. However, the README states the default mode is a safe test payload with an overlay marker, and the capture functionality is framed as a lab simulation. Because the payloading appears built-in and usable but not part of a larger offensive framework, the maturity is best classified as OPERATIONAL. Repository structure: `CVE-2026-9271.py` contains the assessment logic, HTTP capture handler, CLI mode handling, database/reporting support, and likely web UI startup hooks; `README.md` documents the vulnerability, usage, and generated directories (`logs/`, `reports/`, `kim_guardian.db`); `requirements.txt` lists Python dependencies including requests, BeautifulSoup, Flask, and colorama. Overall purpose: authorized assessment of vulnerable WordPress KeepInMind deployments, with both safe validation and optional lab-oriented credential capture components.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.