CVE-2020-36849

CRITICAL

AIT CSV import/export < 3.0.3 - Unauthenticated Arbitrary File Upload via upload-handler.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36849. PoCs published by h00die, including Metasploit module exploits/multi/http/wp_ait_csv_rce.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in the WordPress AIT CSV Import Export plugin (versions <= 3.0.3). It uploads a malicious PHP payload to the server and triggers its execution, resulting in remote code execution.

Description

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for unauthorized attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (1)

metasploit WORKING POC EXCELLENT
by h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_ait_csv_rce.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in the WordPress AIT CSV Import Export plugin (versions <= 3.0.3). It uploads a malicious PHP payload to the server and triggers its execution, resulting in remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress AIT CSV Import Export plugin <= 3.0.3
No auth needed
Prerequisites: Target running WordPress with vulnerable AIT CSV Import Export plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0450
EPSS Percentile 90.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (3)
AIT Themes/AIT CSV import/export < 3.0.3
ait-themes/ait_cvs_import_export < 3.0.3
ait-themes/csv_import_\/_export < 3.0.3
Published Jul 12, 2025
Tracked Since Feb 18, 2026