Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-9698. PoCs published by Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-9698, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the exploit by uploading a malicious file to a vulnerable endpoint.
Description
The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Exploits (2)
The repository contains functional exploit code for CVE-2024-9698, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the exploit by uploading a malicious file to a vulnerable endpoint.
This is a functional exploit for CVE-2024-9698, targeting an arbitrary file upload vulnerability in the Crafthemes Demo Import WordPress plugin (versions ≤ 3.3). It authenticates as an admin, extracts a nonce, and uploads a malicious PHP file to achieve remote code execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H