The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit script (CVE-2024-3673.py) and a README.md for CVE-2024-3673, a Local File Inclusion (LFI) vulnerability in the Web Directory Free WordPress plugin (versions <= 1.7.2). The exploit script automates the process of checking the plugin version by fetching the readme.txt file, verifying if the target is vulnerable, and then exploiting the LFI by sending a crafted POST request to the /wp-admin/admin-ajax.php endpoint. The default payload attempts to read /etc/passwd, but any file path can be specified. The README provides detailed usage instructions, affected versions, mitigation advice, and legal disclaimers. The exploit is operational, requiring only Python and the requests library, and targets WordPress installations with the vulnerable plugin. No hardcoded IPs or domains are present; endpoints are relative to the user-supplied target URL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.