CVE-2024-25096 describes a code injection vulnerability in Canto Inc.'s Canto product, affecting versions up to and including 3.0.7. The vulnerability arises from improper control over the generation of code, allowing an attacker to inject and execute arbitrary code within the context of the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Metasploit exploit module targeting WordPress Canto plugin remote file inclusion leading to unauthenticated RCE (CVE-2023-3452 and CVE-2024-25096). The primary code is a single Ruby Metasploit module (wordpress_canto_plugin_file_include_rce.rb) that: - Fingerprints WordPress via simple content regex. - Checks vulnerability by fetching {TARGETURI}/readme.txt and parsing the 'Stable tag' version, confirming <= 3.0.6, and probing reachability of a selected vulnerable file under {TARGETURI}/includes/lib/{TARGETFILE}. - Exploits by starting an embedded HTTP server (HttpServer::PHPInclude), then sending a GET/POST request to the vulnerable PHP file with either wp_abspath (tree.php/get.php/download.php/detail.php) or abspath (others like sizes.php/copy-media.php) set to the attacker server URL (get_uri). When the target includes the remote URL (requires allow_url_include=On), it executes the served PHP payload and hands off to the Metasploit handler to obtain a session (commonly php/meterpreter/reverse_tcp). Repo structure also includes a docker-compose.yaml and rfi.ini to stand up a local WordPress+MariaDB lab with allow_url_include enabled, plus README instructions for installing specific vulnerable Canto versions and loading the module into Metasploit. No additional exploit code beyond the Metasploit module is present.
Repository contains a Metasploit exploit module implementing unauthenticated RCE against the WordPress Canto plugin (claimed <= 3.0.7) via Remote File Inclusion (RFI) using a controllable include path parameter (wp_abspath). Main code is in rce_exploit_cve_2024_25096.rb, a Metasploit Remote::HttpClient + HttpServer::PHPInclude module. It (1) checks the target by requesting TARGETURI/readme.txt to parse the plugin version (Stable tag) and (2) probes reachability of TARGETURI/includes/lib/TARGETFILE. On exploitation it starts a local HTTP server (SRVHOST/SRVPORT) and sends a GET request to the vulnerable PHP file with wp_abspath set to the attacker server URL (get_uri). When the target fetches /admin.php from the attacker server, the module responds with payload.encoded as application/x-httpd-php, leading to code execution and a reverse session (e.g., php/meterpreter/reverse_tcp). The repo also includes docker-compose.yaml to spin up a WordPress+MariaDB lab and mounts rfi.ini to enable allow_url_include=On, which is necessary for the RFI technique. README.md provides Metasploit usage steps and example run output. Note: the module references CVE-2024-25096 but also incorrectly links to an NVD page for CVE-2023-3452 in References/README naming, suggesting some copy/paste inconsistencies, though the exploit logic targets the Canto plugin path and files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.