CVE-2024-54369
CRITICALThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2024-54369. PoCs published by Boshe99, Nxploited, RandomRobbieBF.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-54369, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit script demonstrates the ability to upload a malicious file to a vulnerable target.
Description
Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.
Exploits (3)
The repository contains functional exploit code for CVE-2024-54369, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit script demonstrates the ability to upload a malicious file to a vulnerable target.
This PoC exploits a missing authorization vulnerability in Zita Site Builder <= 1.0.2, allowing unauthenticated attackers to install and activate arbitrary plugins via a crafted POST request to the vulnerable endpoint.
This PoC demonstrates an unauthorized plugin installation vulnerability in Zita Site Builder for WordPress due to missing capability checks. The provided HTTP request shows how an unauthenticated attacker can install arbitrary plugins via the REST API endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H