Exploitation Summary
EIP tracks 3 public exploits for CVE-2024-49328. PoCs published by RandomRobbieBF, Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains a functional proof-of-concept for CVE-2024-49328, demonstrating an unauthenticated privilege escalation vulnerability in the WP REST API FNS plugin for WordPress. The PoC includes a crafted HTTP POST request to register a user with administrator privileges.
Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.
Exploits (3)
The repository contains a functional proof-of-concept for CVE-2024-49328, demonstrating an unauthenticated privilege escalation vulnerability in the WP REST API FNS plugin for WordPress. The PoC includes a crafted HTTP POST request to register a user with administrator privileges.
The repository contains functional exploit code for CVE-2024-49328, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit script demonstrates the ability to upload a malicious file to a vulnerable target.
This repository contains a functional exploit for CVE-2024-49328, a privilege escalation vulnerability in the WP REST API FNS Plugin for WordPress (versions ≤ 1.0.0). The exploit registers a new admin user by sending a crafted POST request to the vulnerable API endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H