CVE-2024-10586

CRITICAL EXPLOITED

WordPress Debug Tool <2.3 - RCE

Title source: llm

Description

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution. CVE-2024-52416 may be a duplicate of this issue.

Exploits (3)

nomisec WORKING POC 1 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2024-10586
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-10586-Poc
nomisec WORKING POC
by Nxploited · remote
https://github.com/Nxploited/CVE-2024-10586-Poc

Scores

CVSS v3 9.8
EPSS 0.5892
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-07-18
CWE
CWE-862
Status published
Products (1)
eugenbobrowski/Debug Tool < 2.2
Published Nov 09, 2024
Tracked Since Feb 18, 2026