CVE-2024-27956

CRITICAL EXPLOITED NUCLEI

WordPress Automatic Plugin <= 3.92.0 - SQL Injection

Title source: nuclei

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

Exploits (19)

nomisec WORKING POC 116 stars
by AiGptCode · remote
https://github.com/AiGptCode/WordPress-Auto-Admin-Account-and-Reverse-Shell-cve-2024-27956
nomisec WORKING POC 89 stars
by diego-tella · remote
https://github.com/diego-tella/CVE-2024-27956-RCE
nomisec WORKING POC 7 stars
by ThatNotEasy · remote
https://github.com/ThatNotEasy/CVE-2024-27956
nomisec SCANNER 2 stars
by Cappricio-Securities · infoleak
https://github.com/Cappricio-Securities/CVE-2024-27956
nomisec WORKING POC 2 stars
by itzheartzz · remote
https://github.com/itzheartzz/MASS-CVE-2024-27956
nomisec WORKING POC 2 stars
by truonghuuphuc · remote
https://github.com/truonghuuphuc/CVE-2024-27956
nomisec WORKING POC 1 stars
by devsec23 · remote
https://github.com/devsec23/CVE-2024-27956
nomisec SUSPICIOUS 1 stars
by FoxyProxys · poc
https://github.com/FoxyProxys/CVE-2024-27956
nomisec WORKING POC
by 0axz-tools · infoleak
https://github.com/0axz-tools/CVE-2024-27956
nomisec WORKING POC
by m4nInTh3mIdDle · remote
https://github.com/m4nInTh3mIdDle/wordpress-CVE-2024-27956
nomisec SCANNER
by 7aRanchi · infoleak
https://github.com/7aRanchi/CVE-2024-27956-for-fscan
nomisec WORKING POC
by CERTologists · remote
https://github.com/CERTologists/EXPLOITING-CVE-2024-27956
nomisec WORKING POC
by cve-2024 · remote
https://github.com/cve-2024/CVE-2024-27956-RCE
nomisec WORKING POC
by hitazuranahiro · poc
https://github.com/hitazuranahiro/Valve-Press-CVE-2024-27956-RCE
nomisec WORKING POC
by W3BW · remote
https://github.com/W3BW/CVE-2024-27956-RCE-File-Package
nomisec STUB
by k3ppf0r · poc
https://github.com/k3ppf0r/CVE-2024-27956
nomisec WORKING POC
by X-Projetion · remote
https://github.com/X-Projetion/CVE-2024-27956-WORDPRESS-RCE-PLUGIN
vulncheck_xdb WORKING POC
remote
https://github.com/TadashiJei/Valve-Press-CVE-2024-27956-RCE
metasploit WORKING POC EXCELLENT
by Rafie Muhammad, Valentin Lobstein · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_automatic_sqli_to_rce.rb

Nuclei Templates (1)

WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CRITICALVERIFIEDby DhiyaneshDK

Scores

CVSS v3 9.9
EPSS 0.9382
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

Details

VulnCheck KEV 2024-04-24
CWE
CWE-89
Status published
Products (1)
valvepress/automatic < 3.92.0
Published Mar 21, 2024
Tracked Since Feb 18, 2026