CVE-2024-9224

MEDIUM

Hello World < 2.1.1 - Authenticated Arbitrary File Read via hello_world_lyric()

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-9224. PoCs published by certuscyber, RandomRobbieBF.

AI-analyzed exploit summary The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). Each PoC includes detailed steps, authentication handling, and payload delivery.

Description

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Exploits (2)

github WORKING POC 3 stars
by certuscyber · pythonpoc
https://github.com/certuscyber/cve-pocs/tree/main/CVE-2024-9224

The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). Each PoC includes detailed steps, authentication handling, and payload delivery.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress YAWPP plugin <= 1.2, WordPress Quartz plugin <= 1.01.1, Five Star Restaurant Menu and Food Ordering plugin <= 2.2.0
Auth required
Prerequisites: WordPress admin/contributor credentials · Target plugin installed and activated
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9224

This PoC exploits an authenticated arbitrary file read vulnerability in the Hello World WordPress plugin (versions <= 2.1.1) via the hello_world_lyric() function. It logs in as a subscriber-level user and reads arbitrary files by manipulating the nonce and payload.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Hello World WordPress plugin <= 2.1.1
Auth required
Prerequisites: Valid WordPress credentials (subscriber+) · Hello World plugin installed and activated
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0140
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
kau-boy/Hello World < 2.1.1
kau-boys/hello_world < 2.2.0
Published Oct 01, 2024
Tracked Since Feb 18, 2026