CVE-2019-8942 is an authenticated vulnerability in WordPress before 4.9.9 and 5.x before 5.0.1 that can be used to achieve remote code execution through improper handling of attachment metadata during image processing workflows. The flaw allows an attacker with author-level privileges to modify the _wp_attached_file post meta value to an arbitrary string, including a value crafted to influence how WordPress handles uploaded image files during crop operations. By uploading a malicious image containing PHP code in Exif metadata and then manipulating the attachment path metadata, an attacker can cause server-side creation or placement of a file in a way that results in executable PHP content being reachable. Public reporting also notes that exploitation can be chained with CVE-2019-8943 to improve reliability or reachability of the attack path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains two standalone Python exploit scripts for the authenticated WordPress crop-image RCE chain combining CVE-2019-8942 and CVE-2019-8943. It is not part of a larger exploitation framework. Structure is minimal: README documentation, two Python scripts, and requirements.txt. The main purpose is to exploit vulnerable WordPress versions using valid credentials with media permissions. exploit_oscp.py is the manual/OSCP-oriented workflow. It authenticates to WordPress, detects the active theme, uploads a crafted JPEG carrier, extracts required nonces, abuses attachment metadata/path traversal during crop operations to place a PHP-capable image into the active theme directory, creates a post that references the cropped image as a page template, confirms command execution via GET parameter 0, and finally triggers a reverse shell to an operator-managed nc listener. It supports proxies, custom/random User-Agent, timeout tuning, and debug artifact saving. autoexploit.py implements the same exploitation chain but adds operational automation: embedded GD-safe JPEG carrier, automatic callback IP/port selection, local listener startup on 0.0.0.0, multiple reverse-shell payload attempts, and an interactive shell console/TTY handling. The embedded payload stub is a compact PHP command-execution primitive (<?=`$_GET[0]`;?>), which is then used to run shell commands on the target. Fingerprintable targets/endpoints are primarily WordPress web paths: wp-login.php, wp-admin/, wp-admin/media-new.php, async-upload.php, and theme paths under /wp-content/themes/. The exploit also manipulates WordPress metadata keys _wp_attached_file and _wp_page_template. Local artifacts include debug_payload_upload.jpg and debug HTML files. Overall, this is a real authenticated web exploit with practical RCE and reverse-shell capability, suitable for lab exploitation rather than mere detection.
Repository contains two standalone Python exploit implementations for the authenticated WordPress crop-image RCE chain (CVE-2019-8942/CVE-2019-8943): `exploit_oscp.py` for manual/OSCP-style operation and `autoexploit.py` for automated exploitation with an integrated listener and interactive shell handling. Both scripts use `requests`, disable TLS verification warnings, support proxies and custom/random User-Agent strings, and authenticate to WordPress before executing the exploit chain. Core exploit purpose: abuse WordPress media handling and crop functionality to upload a crafted JPEG containing embedded PHP (`<?=`$_GET[0]`;?>`), manipulate attachment metadata/pathing so the cropped output lands in the active theme directory, set the cropped image as a page template via `_wp_page_template`, then request the post to force WordPress to include the image as PHP. This yields authenticated command execution through GET parameter `0`, which is then used to launch a reverse shell. Repository structure is simple: `README.md` documents usage and the exploitation flow; `requirements.txt` specifies `requests[socks]>=2.31.0`; `exploit_oscp.py` is the manual exploit requiring operator-supplied `--lhost` and `--lport` and an external netcat listener; `autoexploit.py` is the more feature-rich variant that embeds a GD-safe JPEG carrier internally, auto-selects callback IP/port when possible, iterates through reverse-shell payload attempts, binds a local listener on `0.0.0.0`, and provides interactive shell handling. Notable capabilities observed from code and README: WordPress login, active theme detection, nonce extraction, media upload to `async-upload.php`, attachment metadata abuse (`_wp_attached_file`), crop-triggering, post creation, template assignment (`_wp_page_template`), command execution verification, reverse-shell triggering, proxy support, debug artifact generation, and in the automated script, listener management and shell interaction. This is a real exploit repository, not merely a detector or documentation.
This repository contains a single Metasploit module (wp_crop_rce.rb) that exploits a path traversal and local file inclusion vulnerability in WordPress versions 5.0.0 and <= 4.9.8 (CVE-2019-8942, CVE-2019-8943). The exploit requires valid WordPress credentials with at least author privileges. It abuses the crop-image functionality to upload a malicious image, then leverages path traversal to place a PHP shell in the active theme directory. The module interacts with several WordPress admin endpoints (media-new.php, post.php, admin-ajax.php) to perform the attack. Upon successful exploitation, the attacker gains remote code execution as the web server user. The module is operational and leaves artifacts on disk and in logs. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository provides a proof-of-concept (PoC) exploit for WordPress remote code execution vulnerabilities CVE-2019-8942 and CVE-2019-8943, affecting WordPress versions <= 4.9.8 and <= 5.0.0. The exploit leverages the image upload and editing functionality available to users with 'author' privileges. By embedding a PHP payload in the metadata of an image file (using exiftool), uploading it, and manipulating WordPress's media handling endpoints, an attacker can achieve arbitrary code execution on the server. The repository includes a Docker environment for easy setup, with configuration files for WordPress and MySQL, and a sample database. The main exploit steps are detailed in the README, which also provides example HTTP requests and payloads. The attack is performed over HTTP(S) endpoints, and the payload is a simple PHP webshell. No detection scripts or framework code are present; this is a standalone PoC with a focus on demonstrating the vulnerability and providing a reproducible test environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated path traversal vulnerability affecting WordPress versions prior to 5.0.1.
A remote code execution vulnerability in WordPress image cropping functionality that affects WordPress 5.0.0 and earlier, allowing an authenticated author-level or higher user to manipulate image crop paths and achieve code execution.
Specific vulnerability listed as an example in EPSS probability rankings; the content does not describe the flaw itself.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.