CVE-2024-54262
CRITICALSiddharth Nagar Import Export For WooCommerce <1.5 - RCE
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2024-54262. PoCs published by Boshe99, Nxploited, RandomRobbieBF.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-54262, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable target.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.
Exploits (3)
The repository contains functional exploit code for CVE-2024-54262, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable target.
This is a functional exploit for CVE-2024-54262, targeting an arbitrary file upload vulnerability in the 'Import Export for WooCommerce' WordPress plugin (versions <= 1.5). It includes version detection, authentication, and file upload capabilities for remote code execution.
This PoC demonstrates an authenticated arbitrary file upload vulnerability in the Import Export For WooCommerce plugin (v1.5), allowing Subscriber+ users to upload malicious PHP files via a multipart/form-data request to admin-ajax.php.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H