Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2024-27954 PoC β€” WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability

Source
Associated Vulnerability
Title:WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability (CVE-2024-27954)
Description:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.
Readme
# CVE-2024-27954


# πŸ“ CVE-2024-27954 - Path Traversal & SSRF Vulnerability in WP Automatic Plugin

### Description
An **Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')** vulnerability exists in the WP Automatic plugin, allowing **Path Traversal** and **Server-Side Request Forgery (SSRF)** attacks. This issue affects WP Automatic versions up to **3.92.0**.

---

### πŸ” Detection Queries

To identify affected hosts, you can use the following queries:

- **FOFA:** `body="wp-content/plugins/wp-automatic" && header="HTTP/1.1 200 OK"`
- **ZoomEye:** `title:"wp-automatic" response.status_code:200`
- **Shodan:** `http.title:"wp-automatic" http.status:200`
- **Publicwww:** `"/wp-content/plugins/wp-automatic"`

---

### ⬇️ Installation

Clone the repository:

```bash
git clone https://github.com/Quantum-Hacker/CVE-2024-27954.git
cd CVE-2024-27954

Nuclei Usage:
Use Nuclei with the provided template:
nuclei -t wprce.yaml --target http://example.com or -l WPUrls.txt


⚠️ Disclaimer
This tool is intended for authorized security testing and educational purposes only. Unauthorized use against systems is strictly prohibited.

πŸ“„ License
This tool is licensed under the MIT License.
File Snapshot

[4.0K] /data/pocs/87cf8e1fde78a426d3bcd4eb714b0c029bfd3156 β”œβ”€β”€ [1.2K] README.md └── [ 661] wprce.yaml 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers β€” if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online β€” thank you for the support. View subscription plans β†’