← back
CVE-2024-27956criticalobserved exploitationCWE-89

WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.9epss 94%
from disclosure to weapon37 days
Published on NVDMar 21
1st PoC+37d
metasploitMar 13
VulnCheck+34d
exploitation probability
94%top 1% of all CVEs
observed exploitation
yesVulnCheck
31 public exploit(s)
In short

The WordPress Automatic plugin allows attackers to execute arbitrary SQL commands without needing to log in, potentially exposing or modifying sensitive database information. This happens because the plugin does not properly validate user input before using it in database queries.

Technical detail

CWE-89 SQL Injection vulnerability in Automatic plugin versions up to 3.92.0 allows unauthenticated attackers to inject malicious SQL commands through inadequately sanitized input parameters. Successful exploitation enables unauthorized database access, data exfiltration, or modification without requiring valid credentials.

Summary generated and translated by AI from the official description.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Affected products
ValvePress · Automatic
public PoCs found31
githubgithub.com/diego-tella/CVE-2024-27956-RCE90githubgithub.com/Ap0dexMe0/CVE-2024-279568githubgithub.com/itzheartzz/MASS-CVE-2024-279563githubgithub.com/Cappricio-Securities/CVE-2024-279562githubgithub.com/truonghuuphuc/CVE-2024-279562githubgithub.com/FoxyProxys/CVE-2024-279561githubgithub.com/devsec23/CVE-2024-279561githubgithub.com/7aRanchi/CVE-2024-27956-for-fscan0githubgithub.com/m4nInTh3mIdDle/wordpress-CVE-2024-279560githubgithub.com/0axz-tools/CVE-2024-279560githubgithub.com/X-Projetion/CVE-2024-27956-WORDPRESS-RCE-PLUGIN0githubgithub.com/k3ppf0r/CVE-2024-279560githubgithub.com/W3BW/CVE-2024-27956-RCE-File-Package0githubgithub.com/hitazuranahiro/Valve-Press-CVE-2024-27956-RCE0githubgithub.com/cve-2024/CVE-2024-27956-RCE0githubgithub.com/CERTologists/EXPLOITING-CVE-2024-279560vulncheckvulncheck.com/xdb/68f086605e61unverifiedvulncheckvulncheck.com/xdb/23332f12d7daunverifiedvulncheckvulncheck.com/xdb/6141dc1c2fd0unverifiedvulncheckvulncheck.com/xdb/c213e3cf0599unverifiedvulncheckvulncheck.com/xdb/96f8fb6c286eunverifiedvulncheckvulncheck.com/xdb/47fdf7489fbfunverifiedvulncheckvulncheck.com/xdb/ee5ad81bbd31unverifiedvulncheckvulncheck.com/xdb/00ceb5c17386unverifiedvulncheckvulncheck.com/xdb/f1969acd14dfunverifiedvulncheckvulncheck.com/xdb/c2bee21d4146unverifiedvulncheckvulncheck.com/xdb/541234df3b1aunverifiedvulncheckvulncheck.com/xdb/195cd4df2bdfunverifiedvulncheckvulncheck.com/xdb/e23e19a6e213unverifiedvulncheckvulncheck.com/xdb/799f8a79b8afunverifiedvulncheckvulncheck.com/xdb/ee7e0f0a304funverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.