NA

CVE-2024-27956

Published: 21/03/2024 Updated: 29/04/2024

Vulnerability Summary

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a up to and including 3.92.0.

Vulnerability Trend

Github Repositories

PoC for wordpress takeover in CVE-2024-27956

CVE-2024-27956-RCE PoC for wordpress takeover in CVE-2024-27956

CVE-2024-27956 WORDPRESS RCE PLUGIN

CVE-2024-27956-WORDPRESS-RCE-PLUGIN CVE-2024-27956 WORDPRESS RCE PLUGIN

CVE-2024-27956

CVE-2024-27956 CVE-2024-27956

WordPress Auto Admin Account Creation and Reverse Shell cve-2024-27956 automates the process of creating a new administrator account in a WordPress site and executing a reverse shell on the target server. It utilizes the wp-automatic plugin's CSV injection vulnerability to execute SQL queries

WordPress Admin Account Creation and Reverse Shell (cve-2024-27956) This Python script automates the process of creating a new administrator account in a WordPress site and executing a reverse shell on the target server It utilizes the wp-automatic plugin's CSV injection vulnerability to execute SQL queries on the WordPress database and gain administrative access Prerequ

CVE-2024-27956-RCE File Package Contents: exploitpy (Original Creator:GitHubcom/diego-tella) modified_exploitpy (Modified with an ignore ssl verification option) Screenshot wpValvePresspluginpy (Python script using URI parameters to search for vulnerable wp plugin)

Recent Articles

Hackers exploit LiteSpeed Cache flaw to create WordPress admins
BleepingComputer • Bill Toulas • 07 May 2024

Hackers exploit LiteSpeed Cache flaw to create WordPress admins By Bill Toulas May 7, 2024 05:42 PM 0 Hackers have been targeting WordPress sites with an outdated version of the LiteSpeed Cache plugin to create administrator users and gain control of the websites. LiteSpeed Cache (LS Cache) is advertised as a caching plugin used in over five million WordPress sites that helps speed up page loads, improve visitor experience, and boost Google Search ranking. Automattic's security te...

WP Automatic WordPress plugin hit by millions of SQL injection attacks
BleepingComputer • Bill Toulas • 25 Apr 2024

WP Automatic WordPress plugin hit by millions of SQL injection attacks By Bill Toulas April 25, 2024 10:27 AM 0 Hackers have started to target a critical severity vulnerability in the WP Automatic plugin for WordPress to create user accounts with administrative privileges and to plant backdoors for long-term access. Currently installed on more than 30,000 websites, WP Automatic lets administrators automate content importing (e.g. text, images, video) from various online sources and publishing on...