The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins that can be leveraged to exploit other vulnerabilities.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (CVE-2024-10578.py) targeting a vulnerability (CVE-2024-10578) in the Pubnews WordPress theme (versions <= 1.0.7). The vulnerability allows authenticated users (Subscriber-level or higher) to install arbitrary plugins due to missing capability checks. The script automates the exploitation process: it logs into the target WordPress site, extracts a required CSRF token (_wpnonce) from the admin page, and then triggers the vulnerable AJAX action to install a plugin from an attacker-supplied URL. The attacker must provide a zip file containing a malicious plugin (such as a webshell), which will be installed and extracted on the target server. The script provides clear output on success or failure and highlights the location of the installed shell. The repository includes a README with usage instructions and a license file. The main attack vector is network-based, targeting WordPress administrative endpoints. No detection or fake code is present; this is a functional exploit script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.