CVE-2024-9932

Published Oct 26, 2024

Last updated 5 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-9932 is an arbitrary file upload vulnerability found in the Wux Blog Editor plugin for WordPress. This flaw exists in the `wuxbt_insertImageNew` function across all versions up to and including 3.0.0. The vulnerability stems from insufficient validation of file types, which allows unauthenticated attackers to upload arbitrary files to the affected server. This unauthorized file upload can potentially lead to remote code execution on the compromised system.

Description
The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-434

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

9

  1. ‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://t.co/YXedHSR2sE Type: 0-Click RCE Exploit Usage: python https://t.co/f1vxFuIOLi --target https://t.c

    @DarkWebInformer

    27 Jan 2026

    5117 Impressions

    22 Retweets

    71 Likes

    37 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 ALERTA CRÍTICA: Plugin de WordPress (CVE-2024-9932) 🚨 ⚠️ Una vulnerabilidad en el plugin Wux Blog Editor (hasta la versión 3.0.0) permite a atacantes subir archivos maliciosos y ejecutar código en tu servidor. 😱 Impacto: •Gravedad: CRÍTICA (CVSS 9.8) •Ataque remoto sin… ht

    @tpx_Security

    18 Nov 2024

    165 Impressions

    3 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 0-Click RCE (Unauthenticated/Pre-Auth) Exploit for CVE-2024-9932 😇 #Wordpress #BugBounty https://t.co/noLpQn4Tnn

    @JoshuaProvoste

    18 Nov 2024

    18039 Impressions

    46 Retweets

    279 Likes

    131 Bookmarks

    2 Replies

    1 Quote

  4. [CVE-2024-9932: CRITICAL] WordPress Wux Blog Editor plugin (up to 3.0.0) has a security flaw allowing unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.#cybersecurity,#vulnerability https://t.co/pAUvGOUxpD https://t.co/1cCRI0R9Ec

    @CveFindCom

    26 Oct 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-9932 The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in vers… https://t.co/7MU2Zjz0zU

    @CVEnew

    26 Oct 2024

    530 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes