CVE-2024-43160
CRITICAL NUCLEIBerqWP < 1.7.6 - Unauthenticated Arbitrary File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-43160. PoCs published by KTN1990. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-43160, an unauthenticated arbitrary file upload vulnerability in the BerqWP WordPress plugin (versions <= 1.7.6). The exploit uploads a PHP shell via the `/wp-json/optifer/v1/store-webp` endpoint and verifies successful upload by checking for a specific string in the response.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.
Exploits (1)
This repository contains a functional exploit for CVE-2024-43160, an unauthenticated arbitrary file upload vulnerability in the BerqWP WordPress plugin (versions <= 1.7.6). The exploit uploads a PHP shell via the `/wp-json/optifer/v1/store-webp` endpoint and verifies successful upload by checking for a specific string in the response.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H