Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-10674. PoCs published by Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-10674, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the exploit by uploading a shell file to a vulnerable endpoint.
Description
The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.
Exploits (2)
The repository contains functional exploit code for CVE-2024-10674, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the exploit by uploading a shell file to a vulnerable endpoint.
This repository contains a functional exploit for CVE-2024-10674, which allows authenticated users with Subscriber-level access to install and activate arbitrary plugins in the Th Shop Mania WordPress theme (versions <= 1.4.9). The exploit automates the process of checking vulnerability, authenticating, and installing/activating a specified plugin.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H