CVE-2024-6651

MEDIUM NUCLEI

WordPress File Upload <4.24.8 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-6651. PoCs published by yup-Ivan. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2024-6651, a reflected XSS vulnerability in the WP File Upload WordPress plugin versions prior to 4.24.8. The exploit leverages an unsanitized 'dir' parameter in the File Browser functionality to execute arbitrary JavaScript in the context of an authenticated user.

Description

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Exploits (1)

nomisec WORKING POC 1 stars
by yup-Ivan · poc
https://github.com/yup-Ivan/CVE-2024-6651

This repository contains a functional proof-of-concept for CVE-2024-6651, a reflected XSS vulnerability in the WP File Upload WordPress plugin versions prior to 4.24.8. The exploit leverages an unsanitized 'dir' parameter in the File Browser functionality to execute arbitrary JavaScript in the context of an authenticated user.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WP File Upload < 4.24.8
Auth required
Prerequisites: WordPress with vulnerable WP File Upload plugin · Authenticated user session (typically admin)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting
HIGHby ritikchaddha
FOFA: body='wp-content/plugins/wp-file-upload/'

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/65e2c77d-09bd-4a44-81d9-d7a5db0e0f84/

Scores

CVSS v3 6.1
EPSS 0.1543
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
iptanus/wordpress_file_upload < 4.24.8
Published Aug 06, 2024
Tracked Since Feb 18, 2026