Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
2
2
1
1
1
Platforms
1
1
1
Products / Services
1
1
1
MITRE Techniques
2
1
1
1
CVEs
68
68
60
58
50
This rule detects the creation of a new WordPress administrator account within a short window (15 minutes) of an anomalous authentication or registration event on the same account or session. It is designed to identify post-exploitation activity, specifically persistence mechanisms following the exploitation of web application vulnerabilities like arbitrary file uploads or authentication bypasses in WordPress plugins.
This rule detects potential exploitation of CVE-2026-15826, an authentication bypass vulnerability in the WordPress User Profile Builder plugin. It monitors HTTP POST requests to 'admin-ajax.php' or the 'profile-builder' endpoint for username parameters between 61 and 70 characters long, which is a known exploit condition for triggering a type confusion in the wppb_log_in_user() function that could allow unauthorized access as user ID 1.
Detects unauthenticated WordPress administrator account takeover attempts targeting the User Profile Builder plugin. The rule identifies inbound HTTP GET requests containing the 'autologin=true' parameter and a forged '_wpnonce' value matching the 'autologin-1-' pattern, which exploits an authentication bypass vulnerability (CVE-2026-15826) to gain unauthorized session access as user ID 1.
