In the Workreap WordPress theme prior to version 2.2.2, the AJAX actions 'workreap_award_temp_file_uploader' and 'workreap_temp_file_uploader' failed to implement nonce checks or any form of user validation. This allowed unauthenticated users to upload arbitrary files, including executable PHP scripts, to the 'uploads/workreap-temp' directory. The uploaded files were not sanitized or validated, enabling attackers to upload and execute malicious code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a small Bash-based mass exploitation tool for CVE-2021-24499 affecting the Workreap WordPress theme (<= 2.2.2). Structure: (1) `exploit.sh` is the main entry point; it accepts `-u <url>` for a single target or `-l <file>` for multiple targets, then uses `curl` to POST a multipart form to `TARGET/wp-admin/admin-ajax.php` with `action=workreap_award_temp_file_uploader` and uploads the local `shell.php` as `award_img`. It determines success by grepping the response for the string `File uploaded!`. On success it prints and records the presumed web-accessible payload path `TARGET/wp-content/uploads/workreap-temp/shell.php` into `result.txt`. (2) `shell.php` is a minimal PHP command-execution payload that runs `id` when requested, serving as an RCE proof. (3) `list.txt` is a sample targets list. (4) `README.md` documents the vulnerability, usage, and references. Overall purpose: automate unauthenticated arbitrary file upload leading to RCE by planting a PHP payload in the Workreap temporary upload directory and providing the resulting shell URL(s).
This repository provides an exploit for CVE-2021-24499, a vulnerability in the Workreap WordPress theme that allows unauthenticated file uploads via specific AJAX actions. The repository contains three files: a README.md describing the vulnerability, an exploit.sh Bash script that automates exploitation against a list of targets, and a shell.php PHP webshell payload. The exploit script uploads the webshell to the vulnerable endpoint (/wp-admin/admin-ajax.php) using the 'workreap_award_temp_file_uploader' action, and if successful, the shell is accessible at /wp-content/uploads/workreap-temp/shell.php. The webshell allows remote command execution via the 'CMD' GET parameter. The exploit is operational and can be used for mass exploitation of vulnerable WordPress sites running the affected Workreap theme.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.