CVE-2024-0509

MEDIUM

WP 404 Auto Redirect to Similar Post < 1.0.3 - Unauthenticated Reflected Cross-Site Scripting via Request Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-0509. PoCs published by kodaichodai.

AI-analyzed exploit summary This is a functional CSRF PoC for CVE-2024-0509, exploiting a WordPress plugin vulnerability via a crafted AJAX request to trigger XSS. The exploit uses a form to submit a malicious payload to the target's admin-ajax.php endpoint.

Description

The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Exploits (1)

nomisec WORKING POC
by kodaichodai · poc
https://github.com/kodaichodai/CVE-2024-0509

This is a functional CSRF PoC for CVE-2024-0509, exploiting a WordPress plugin vulnerability via a crafted AJAX request to trigger XSS. The exploit uses a form to submit a malicious payload to the target's admin-ajax.php endpoint.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress (specific plugin not explicitly named in code)
No auth needed
Prerequisites: Target must have vulnerable WordPress plugin installed · Victim must interact with the crafted form
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0123
EPSS Percentile 65.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
hwk/wp_404_auto_redirect_to_similar_post < 1.0.3
hwk-fr/WP 404 Auto Redirect to Similar Post < 1.0.3
Published Feb 05, 2024
Tracked Since Feb 18, 2026