CVE-2024-0757

MEDIUM

WordPress Plugin <4.3000000023 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-0757. PoCs published by hunThubSpace.

AI-analyzed exploit summary The repository contains a functional exploit for CVE-2024-0757, which leverages an arbitrary file upload vulnerability in the 'Insert or Embed Articulate Content into WordPress' plugin. The exploit uploads a malicious ZIP file containing a PHAR file, leading to potential remote code execution (RCE) on vulnerable WordPress installations.

Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

Exploits (1)

nomisec WORKING POC 8 stars
by hunThubSpace · poc
https://github.com/hunThubSpace/CVE-2024-0757-Exploit

The repository contains a functional exploit for CVE-2024-0757, which leverages an arbitrary file upload vulnerability in the 'Insert or Embed Articulate Content into WordPress' plugin. The exploit uploads a malicious ZIP file containing a PHAR file, leading to potential remote code execution (RCE) on vulnerable WordPress installations.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Insert or Embed Articulate Content into WordPress plugin <= 4.3000000023
Auth required
Prerequisites: Valid WordPress credentials · Network access to the target WordPress site
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/eccd017c-e442-46b6-b5e6-aec7bbd5f836/

Scores

CVSS v3 5.4
EPSS 0.0094
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
elearningfreak/insert_or_embed_articulate_content < 4.3000000023
Published Jun 04, 2024
Tracked Since Feb 18, 2026