CVE-2024-10586

CRITICAL EXPLOITED

WordPress Debug Tool <2.3 - RCE

Title source: llm

Description

The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution.

Exploits (3)

nomisec WORKING POC 1 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2024-10586
nomisec WORKING POC
by Nxploited · remote
https://github.com/Nxploited/CVE-2024-10586-Poc
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-10586-Poc

Scores

CVSS v3 9.8
EPSS 0.5272
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2025-07-18

Classification

CWE
CWE-862
Status draft

Timeline

Published Nov 09, 2024
Tracked Since Feb 18, 2026