CVE-2024-9932
Published Oct 26, 2024
Last updated 2 months ago
- Description
- The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Source
- security@wordfence.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-434
- Hype score
- Not currently trending
‼️ CVE-2024-9932: Kerentanan unggahan file sembarangan tanpa otentikasi pada plugin WordPress Wux Blog Editor, yang menyebabkan eksekusi perintah jarak jauh (RCE). GitHub: https://t.co/TjkO3YhwyI… Tipe: Eksploitasi RCE 0-Klik Penggunaan: python https://t.co/m0MKzJdtsd ht
@BJORKANISM_REAL
29 Jan 2026
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://t.co/YXedHSR2sE Type: 0-Click RCE Exploit Usage: python https://t.co/f1vxFuIOLi --target https://t.c
@DarkWebInformer
27 Jan 2026
5117 Impressions
22 Retweets
71 Likes
37 Bookmarks
0 Replies
0 Quotes
🚨 ALERTA CRÍTICA: Plugin de WordPress (CVE-2024-9932) 🚨 ⚠️ Una vulnerabilidad en el plugin Wux Blog Editor (hasta la versión 3.0.0) permite a atacantes subir archivos maliciosos y ejecutar código en tu servidor. 😱 Impacto: •Gravedad: CRÍTICA (CVSS 9.8) •Ataque remoto sin… ht
@tpx_Security
18 Nov 2024
165 Impressions
3 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Click RCE (Unauthenticated/Pre-Auth) Exploit for CVE-2024-9932 😇 #Wordpress #BugBounty https://t.co/noLpQn4Tnn
@JoshuaProvoste
18 Nov 2024
18039 Impressions
46 Retweets
279 Likes
131 Bookmarks
2 Replies
1 Quote
[CVE-2024-9932: CRITICAL] WordPress Wux Blog Editor plugin (up to 3.0.0) has a security flaw allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.#cybersecurity,#vulnerability https://t.co/pAUvGOUxpD https://t.co/1cCRI0R9Ec
@CveFindCom
26 Oct 2024
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in vers… https://t.co/7MU2Zjz0zU
@CVEnew
26 Oct 2024
530 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes