CVE-2015-10137

CRITICAL

Website Contact Form With File Upload <1.3.4 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-10137. PoCs published by Kai-One001, Claudio Viviani, including Metasploit module exploits/unix/webapp/wp_nmediawebsite_file_upload.

AI-analyzed exploit summary This is a functional exploit for CVE-2015-10137, targeting a file upload vulnerability in WordPress N-Media Website Contact Form with File Uploader 1.3.4. It uploads a PHP webshell and provides an interactive shell for remote command execution.

Description

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (2)

nomisec WORKING POC
by Kai-One001 · poc
https://github.com/Kai-One001/-CVE-2015-10137-WordPress-N-Media-Website-Contact-Form-with-File-Upload-1.3.4

This is a functional exploit for CVE-2015-10137, targeting a file upload vulnerability in WordPress N-Media Website Contact Form with File Uploader 1.3.4. It uploads a PHP webshell and provides an interactive shell for remote command execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress N-Media Website Contact Form with File Uploader 1.3.4
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and activated · Upload directory must be web-accessible and PHP execution must be allowed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Claudio Viviani · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_nmediawebsite_file_upload.rb

This Metasploit module exploits an arbitrary file upload vulnerability in the WordPress N-Media Website Contact Form plugin (version 1.3.4), allowing remote code execution via a malicious PHP file upload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress N-Media Website Contact Form plugin v1.3.4
No auth needed
Prerequisites: Target running vulnerable WordPress plugin · Network access to WordPress admin-ajax.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7921
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (2)
N-Media/Website Contact Form With File Upload < 1.3.4
najeebmedia/website_contact_form_with_file_upload < 1.3.4
Published Jul 22, 2025
Tracked Since Feb 18, 2026