AI description
CVE-2024-9932 is an arbitrary file upload vulnerability found in the Wux Blog Editor plugin for WordPress. This flaw exists in the `wuxbt_insertImageNew` function across all versions up to and including 3.0.0. The vulnerability stems from insufficient validation of file types, which allows unauthenticated attackers to upload arbitrary files to the affected server. This unauthorized file upload can potentially lead to remote code execution on the compromised system.
- Description
- The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Source
- security@wordfence.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-434
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://t.co/YXedHSR2sE Type: 0-Click RCE Exploit Usage: python https://t.co/f1vxFuIOLi --target https://t.c
@DarkWebInformer
27 Jan 2026
5117 Impressions
22 Retweets
71 Likes
37 Bookmarks
0 Replies
0 Quotes
🚨 ALERTA CRÍTICA: Plugin de WordPress (CVE-2024-9932) 🚨 ⚠️ Una vulnerabilidad en el plugin Wux Blog Editor (hasta la versión 3.0.0) permite a atacantes subir archivos maliciosos y ejecutar código en tu servidor. 😱 Impacto: •Gravedad: CRÍTICA (CVSS 9.8) •Ataque remoto sin… ht
@tpx_Security
18 Nov 2024
165 Impressions
3 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Click RCE (Unauthenticated/Pre-Auth) Exploit for CVE-2024-9932 😇 #Wordpress #BugBounty https://t.co/noLpQn4Tnn
@JoshuaProvoste
18 Nov 2024
18039 Impressions
46 Retweets
279 Likes
131 Bookmarks
2 Replies
1 Quote
[CVE-2024-9932: CRITICAL] WordPress Wux Blog Editor plugin (up to 3.0.0) has a security flaw allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.#cybersecurity,#vulnerability https://t.co/pAUvGOUxpD https://t.co/1cCRI0R9Ec
@CveFindCom
26 Oct 2024
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in vers… https://t.co/7MU2Zjz0zU
@CVEnew
26 Oct 2024
530 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes