CVE-2024-54369

CRITICAL

ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2024-54369. PoCs published by Boshe99, Nxploited, RandomRobbieBF.

AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-54369, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit script demonstrates the ability to upload a malicious file to a vulnerable target.

Description

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

Exploits (3)

github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-54369-PoC

The repository contains functional exploit code for CVE-2024-54369, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit script demonstrates the ability to upload a malicious file to a vulnerable target.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: target URL · path to the file to be uploaded
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-54369-PoC

This PoC exploits a missing authorization vulnerability in Zita Site Builder <= 1.0.2, allowing unauthenticated attackers to install and activate arbitrary plugins via a crafted POST request to the vulnerable endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Zita Site Builder WordPress plugin <= 1.0.2
No auth needed
Prerequisites: Python 3.x · requests library · target WordPress site with vulnerable plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-54369

This PoC demonstrates an unauthorized plugin installation vulnerability in Zita Site Builder for WordPress due to missing capability checks. The provided HTTP request shows how an unauthenticated attacker can install arbitrary plugins via the REST API endpoint.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Zita Site Builder (ai-site-builder) <= 1.0.2
No auth needed
Prerequisites: WordPress site with Zita Site Builder plugin <= 1.0.2 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0150
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
ThemeHunk/Zita Site Builder < 1.0.2
Published Dec 16, 2024
Tracked Since Feb 18, 2026