CVE-2024-10674

HIGH

Th Shop Mania <1.4.9 - Privilege Escalation

Title source: llm

Description

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.

Exploits (2)

nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-10674
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-10674

Scores

CVSS v3 8.8
EPSS 0.3653
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-862
Status draft

Timeline

Published Nov 09, 2024
Tracked Since Feb 18, 2026