CVE-2024-6318 POC (Proof-of-Concept)

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Published: 2024-07-04

CVSS: 8.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Download CVE-2024-6318 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check my portfolio here:

https://tlncglobal.com/poc-848-cve-2024-50477/

https://tlncglobal.com/poc-513-cve-2024-9061/

https://tlncglobal.com/poc-474-cve-2024-9932/

https://tlncglobal.com/poc-773-cve-2024-5326/