CVE-2024-58349

CRITICAL

WordPress Theme Travelscape 1.0.3 Arbitrary File Upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-58349. PoCs published by Milad karimi.

AI-analyzed exploit summary This script checks for the presence of known webshells and vulnerable files in WordPress installations, specifically targeting the Travelscape theme and other common vulnerable paths. It does not exploit the vulnerability but scans for indicators of compromise.

Description

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.

Exploits (1)

exploitdb SCANNER
by Milad karimi · pythonwebappsphp
https://www.exploit-db.com/exploits/51969

This script checks for the presence of known webshells and vulnerable files in WordPress installations, specifically targeting the Travelscape theme and other common vulnerable paths. It does not exploit the vulnerability but scans for indicators of compromise.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Theme Travelscape v1.0.3
No auth needed
Prerequisites: List of target URLs
devstral-2 · analyzed Jun 08, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-51969
https://www.exploit-db.com/exploits/51969
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Theme Travelscape 1.0.3 Arbitrary File Upload
https://www.vulncheck.com/advisories/wordpress-theme-travelscape-arbitrary-file-upload

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
WP Travel Kit/Travelscape 1.0.3
Published Jun 08, 2026
Tracked Since Jun 08, 2026