Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

This rule detects the creation of a new WordPress administrator account within a short window (15 minutes) of an anomalous authentication or registration event on the same account or session. It is designed to identify post-exploitation activity, specifically persistence mechanisms following the exploitation of web application vulnerabilities like arbitrary file uploads or authentication bypasses in WordPress plugins.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
407
This rule detects potential exploitation of CVE-2026-15826, an authentication bypass vulnerability in the WordPress User Profile Builder plugin. It monitors HTTP POST requests to 'admin-ajax.php' or the 'profile-builder' endpoint for username parameters between 61 and 70 characters long, which is a known exploit condition for triggering a type confusion in the wppb_log_in_user() function that could allow unauthorized access as user ID 1.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
003
Detects unauthenticated WordPress administrator account takeover attempts targeting the User Profile Builder plugin. The rule identifies inbound HTTP GET requests containing the 'autologin=true' parameter and a forged '_wpnonce' value matching the 'autologin-1-' pattern, which exploits an authentication bypass vulnerability (CVE-2026-15826) to gain unauthorized session access as user ID 1.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
002