CVE-2024-9932

Published Oct 26, 2024

Last updated 2 months ago

CVSS critical 9.8
WordPress
Wux Blog Editor

Overview

Description
The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-434

Social media

Hype score
Not currently trending
  1. ‼️ CVE-2024-9932: Kerentanan unggahan file sembarangan tanpa otentikasi pada plugin WordPress Wux Blog Editor, yang menyebabkan eksekusi perintah jarak jauh (RCE). GitHub: https://t.co/TjkO3YhwyI… Tipe: Eksploitasi RCE 0-Klik Penggunaan: python https://t.co/m0MKzJdtsd ht

    @BJORKANISM_REAL

    29 Jan 2026

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://t.co/YXedHSR2sE Type: 0-Click RCE Exploit Usage: python https://t.co/f1vxFuIOLi --target https://t.c

    @DarkWebInformer

    27 Jan 2026

    5117 Impressions

    22 Retweets

    71 Likes

    37 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 ALERTA CRÍTICA: Plugin de WordPress (CVE-2024-9932) 🚨 ⚠️ Una vulnerabilidad en el plugin Wux Blog Editor (hasta la versión 3.0.0) permite a atacantes subir archivos maliciosos y ejecutar código en tu servidor. 😱 Impacto: •Gravedad: CRÍTICA (CVSS 9.8) •Ataque remoto sin… ht

    @tpx_Security

    18 Nov 2024

    165 Impressions

    3 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 0-Click RCE (Unauthenticated/Pre-Auth) Exploit for CVE-2024-9932 😇 #Wordpress #BugBounty https://t.co/noLpQn4Tnn

    @JoshuaProvoste

    18 Nov 2024

    18039 Impressions

    46 Retweets

    279 Likes

    131 Bookmarks

    2 Replies

    1 Quote

  5. [CVE-2024-9932: CRITICAL] WordPress Wux Blog Editor plugin (up to 3.0.0) has a security flaw allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.#cybersecurity,#vulnerability https://t.co/pAUvGOUxpD https://t.co/1cCRI0R9Ec

    @CveFindCom

    26 Oct 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in vers… https://t.co/7MU2Zjz0zU

    @CVEnew

    26 Oct 2024

    530 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes