CVE-2024-27954 is a critical vulnerability in the WP Automatic (Automatic) WordPress plugin (premium version by ValvePress, <3.92.1) that allows unauthenticated attackers to perform path traversal and server-side request forgery (SSRF) via improper validation in the downloader.php file. The flaw enables arbitrary file download from the server and the ability to make arbitrary HTTP requests from the server, potentially exposing sensitive data and enabling further attacks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a working exploit for CVE-2024-27954, targeting the WordPress Automatic plugin versions prior to 3.92.1. The exploit consists of a Python script (RCE_Exploit.py) that automates the process of exploiting a SQL injection vulnerability in the plugin's 'csv.php' endpoint. By sending crafted SQL payloads, the script creates a new administrator user ('eviladmin:admin') on the target WordPress site. The script can process either a single target URL or a list of targets from a file. Additionally, a Nuclei-compatible YAML POC (POC.yaml) is included, which demonstrates the ability to trigger SSRF and arbitrary file download via the vulnerable plugin. The repository also contains a README with usage instructions and a requirements.txt for dependencies. The main attack vector is network-based, exploiting a vulnerable HTTP endpoint. The exploit is operational, providing a working payload that grants full administrative access to the attacker.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.