CVE-2024-52429
CRITICALWP Quick Setup <= 2.0 - Unauthenticated Arbitrary File Upload via Plugin/Theme Installation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-52429. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This PoC demonstrates a missing authorization vulnerability in WP Quick Setup <= 2.0, allowing authenticated subscribers to install arbitrary plugins/themes via an AJAX endpoint. The exploit uses a crafted HTML form to trigger the installation without proper capability checks.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.
Exploits (1)
This PoC demonstrates a missing authorization vulnerability in WP Quick Setup <= 2.0, allowing authenticated subscribers to install arbitrary plugins/themes via an AJAX endpoint. The exploit uses a crafted HTML form to trigger the installation without proper capability checks.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H