CVE-2024-8743

MEDIUM

Bit File Manager < 6.5.7 - Authenticated Limited JavaScript File Upload via Improper File Type Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-8743. PoCs published by siunam321.

AI-analyzed exploit summary This PoC demonstrates a Limited JavaScript File Upload vulnerability in WordPress plugin Bit File Manager (CVE-2024-8743), allowing authenticated attackers with Subscriber+ access to upload malicious .css or .js files, leading to Stored XSS. The exploit includes a Flask server to exfiltrate nonces and a payload generator for CSS-based data extraction.

Description

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an administrator, to upload .css and .js files, which could lead to Stored Cross-Site Scripting.

Exploits (1)

nomisec WORKING POC 2 stars
by siunam321 · poc
https://github.com/siunam321/CVE-2024-8743-PoC

This PoC demonstrates a Limited JavaScript File Upload vulnerability in WordPress plugin Bit File Manager (CVE-2024-8743), allowing authenticated attackers with Subscriber+ access to upload malicious .css or .js files, leading to Stored XSS. The exploit includes a Flask server to exfiltrate nonces and a payload generator for CSS-based data extraction.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Bit File Manager WordPress plugin <= 6.5.7
Auth required
Prerequisites: Subscriber+ WordPress account · File Manager shortcode enabled by administrator
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.8
EPSS 0.0075
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
bitpressadmin/Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress < 6.5.7
bitpressadmin/File Manager < 6.5.7
Published Oct 05, 2024
Tracked Since Feb 18, 2026