The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file upload due to insufficient file type validation in the function wuxbt_insertImageNew in versions up to and including 3.0.0. An unauthenticated attacker can upload arbitrary files to the server; if the uploaded content can be executed by the web server (e.g., PHP in a web-accessible path), this may enable remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a working PoC exploit for CVE-2024-9932 targeting the WordPress Wux Blog Editor plugin. Structure: (1) CVE-2024-9932.py is the main Python exploit. It takes --target (base WP URL), --payload (attacker-controlled URL hosting a PHP payload), and --payload_name (filename to write). It POSTs JSON to /wp-json/external-post-editor/v2/image-upload with {url: <payload_url>, imageName: <payload_name>} to coerce the plugin into fetching and saving the remote file without authentication. It then assumes WordPress’ default uploads path and reconstructs the final URL as /wp-content/uploads/<current_year>/<current_month>/<payload_name>. Next it performs a GET to the uploaded file to read OS info (expects output containing 'windows' or 'linux'), and finally provides an interactive loop that sends commands as GET <upload_url>?cmd=<command> and prints the response. (2) cmd.php is the provided PHP webshell payload: it prints 'System OS: <uname>' when accessed without cmd, and executes arbitrary commands via system($_GET['cmd']) when cmd is present. (3) README.md documents usage and describes the vulnerability as unauthenticated arbitrary file upload leading to RCE. Overall purpose: unauthenticated remote code execution on vulnerable WordPress instances by uploading and interacting with a PHP webshell over HTTP.
This repository contains a Python proof-of-concept exploit for CVE-2024-9932, targeting the Wux Blog Editor WordPress plugin (versions 3.0.0 and below). The exploit leverages an arbitrary file upload vulnerability in the plugin's '/wp-json/external-post-editor/v2/image-upload' API endpoint, which fails to properly validate file types in the 'wuxbt_insertImageNew' function. The exploit script (CVE-2024-9932.py) first checks the plugin version by fetching '/wp-content/plugins/wux-blog-editor/readme.txt' and parsing the 'Stable tag'. If the version is vulnerable, it sends a POST request to the vulnerable API endpoint, instructing the server to fetch and save a file from a remote URL (typically a PHP webshell) under a user-specified name. The script then checks for the presence of the uploaded file in expected upload directories. If successful, the attacker can access and execute the uploaded file, potentially achieving remote code execution. The repository also includes a README.md with usage instructions, vulnerability details, and an example exploit command. The exploit is operational and provides a working method for attackers to compromise vulnerable WordPress installations.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.