CVE-2024-9047

CRITICAL EXPLOITED NUCLEI

WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-9047 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including iSee857, verylazytech, Nxploited. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains functional exploit code for multiple CVEs, including CVE-2026-22812, which demonstrates a command execution vulnerability in OpenCode. The PoC sends crafted requests to exploit the vulnerability and verify command execution via the 'id' command.

Description

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

Exploits (7)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/WordPress_FileUpload (CVE-2024-9047).py

The repository contains functional exploit code for multiple CVEs, including CVE-2026-22812, which demonstrates a command execution vulnerability in OpenCode. The PoC sends crafted requests to exploit the vulnerability and verify command execution via the 'id' command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenCode (version not specified)
No auth needed
Prerequisites: Network access to the target · Target service running and accessible
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 7 stars
by verylazytech · infoleak
https://github.com/verylazytech/CVE-2024-9047

This repository contains a functional proof-of-concept exploit for CVE-2024-9047, targeting a directory traversal vulnerability in the WordPress File Upload plugin (versions <= 4.24.11). The exploit allows unauthenticated users to download arbitrary files from the server's filesystem via improper input validation in the wfu_file_downloader.php file.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress File Upload plugin <= 4.24.11
No auth needed
Prerequisites: Target must have the vulnerable WordPress File Upload plugin installed · Target must be accessible via HTTP
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by iSee857 · infoleak
https://github.com/iSee857/CVE-2024-9047-PoC

This PoC exploits CVE-2024-9047, an arbitrary file read vulnerability in WordPress File Upload plugin versions <= 4.24.11. It checks for the vulnerability by attempting to read /etc/passwd via manipulated cookies and headers.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress File Upload plugin <= 4.24.11
No auth needed
Prerequisites: Target must have WordPress File Upload plugin installed and vulnerable version · Plugin must be accessible at /wp-content/plugins/wp-file-upload/
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Nxploited · remote
https://github.com/Nxploited/CVE-2024-9047-Exploit

This is a functional exploit for CVE-2024-9047, targeting a path traversal vulnerability in the WordPress File Upload plugin (versions up to 4.24.11). It allows unauthenticated attackers to read arbitrary files on the server by manipulating cookies and POST data.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress File Upload plugin <= 4.24.11
No auth needed
Prerequisites: Target must have the vulnerable plugin installed · Server must run PHP 7.4 or earlier
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-9047-Exploit

The repository contains functional exploit code for CVE-2024-9047, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable target.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin 3DPrint Lite 1.9.1.4
No auth needed
Prerequisites: Vulnerable WordPress site with 3DPrint Lite plugin installed
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC
by amirqusairy99 · infoleak
https://github.com/amirqusairy99/WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal

This Python script exploits an unauthenticated path traversal vulnerability in the WordPress WP File Upload plugin (versions <= 4.24.11) to read arbitrary files from the target system. It constructs a malicious request with crafted cookies to bypass restrictions and retrieve file contents.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress WP File Upload plugin <= 4.24.11
No auth needed
Prerequisites: Target must have the vulnerable WP File Upload plugin installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/CVE-2024-9047

The repository contains a README describing CVE-2024-9047, a vulnerability in WordPress File Upload Solution involving arbitrary file access and manipulation via wfu_file_downloader.php. No exploit code or technical details are provided.

Classification
Writeup 30%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: WordPress File Upload Solution (version unspecified)
No auth needed
Prerequisites: Access to wfu_file_downloader.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress File Upload <= 4.24.11 - Arbitrary File Read
CRITICALby s4e-io,S9n3x
Shodan: http.html:"/wp-content/plugins/wp-file-upload/"
FOFA: body="/wp-content/plugins/wp-file-upload"

Scores

CVSS v3 9.8
EPSS 0.9232
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-05-27
CWE
CWE-22
Status published
Products (2)
iptanus/wordpress_file_upload < 4.24.12
nickboss/Iptanus File Upload < 4.24.11
Published Oct 12, 2024
Tracked Since Feb 18, 2026