CVE-2024-10586 affects the Debug Tool plugin for WordPress in all versions up to and including 2.2. The vulnerability is caused by a missing capability check in the dbt_pull_image() function combined with missing file type validation. As a result, unauthenticated attackers can cause the plugin to create arbitrary files on the server, including attacker-controlled PHP files. Because PHP files placed in a web-accessible location can be executed by the server, this arbitrary file creation condition can be leveraged to achieve remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2024-10586, targeting the Debug Tool plugin for WordPress (versions up to and including 2.2). The exploit leverages a vulnerability in the plugin's 'dbt_pull_image' action, which lacks proper capability checks and file type validation, allowing unauthenticated attackers to create arbitrary files on the server. The main script, 'CVE-2024-10586.py', first checks the plugin version by fetching '/wp-content/plugins/debug-tool/readme.txt'. If the version is vulnerable, it sends a crafted POST request to '/wp-admin/admin-ajax.php' with parameters that instruct the plugin to fetch a remote file (typically a PHP webshell) and save it to a specified path (default: '/opt/lampp/htdocs/wordpress/wp-content/Nxploit.php'). The exploit is operational, requiring the attacker to provide the target URL, a remote payload URL, and optionally the destination path. The README provides usage instructions and context. No framework is used; the exploit is a standalone Python script.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.