Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-10673. PoCs published by Nxploited, Boshe99.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-10673, which allows authenticated WordPress users with subscriber-level access to install and activate arbitrary plugins via unprotected AJAX requests in the Top Store WordPress Theme (<= 1.5.4). The exploit automates the attack by dynamically extracting the required nonce and sending crafted requests to install and activate a specified plugin.
Description
The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.
Exploits (2)
This repository contains a functional exploit for CVE-2024-10673, which allows authenticated WordPress users with subscriber-level access to install and activate arbitrary plugins via unprotected AJAX requests in the Top Store WordPress Theme (<= 1.5.4). The exploit automates the attack by dynamically extracting the required nonce and sending crafted requests to install and activate a specified plugin.
The repository contains a functional Python exploit for CVE-2024-10673, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit uploads a malicious file via the vulnerable endpoint and confirms successful upload.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H