Feed/CVE-2024-27956
CVE-2024-27956CRITICALCVSS 9.9

CVE-2024-27956

Published Mar 21, 2024·Updated Jun 17, 2026

NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

Public Exploits & PoCs14 found

PoC: CVE-2024-27956

CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection

13

PoC: WordPress-Auto-Admin-Account-and-Reverse-Shell-cve-2024-27956

WordPress Auto Admin Account Creation and Reverse Shell cve-2024-27956 automates the process of creating a new administrator account in a WordPress site and executing a reverse shell on the target server. It utilizes the wp-automatic plugin's CSV injection vulnerability to execute SQL queries

2

PoC: CVE-2024-27956

CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool

1

PoC: CVE-2024-27956

CVE-2024-27956

PoC: wordpress-CVE-2024-27956

Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).

PoC: CVE-2024-27956-for-fscan

Yaml PoC rule for fscan.

PoC: CVE-2024-27956

Perform with massive Wordpress SQLI 2 RCE

PoC: Valve-Press-CVE-2024-27956-RCE

Valve Press - CVE-2024-27956-RCE - SQL Injection

PoC: CVE-2024-27956

WordPress Automatic Plugin <= 3.92.0 - SQL Injection

PoC: CVE-2024-27956

CVE-2024-27956-RCE-POC-Wordpress, Wordpress, CVE-2024-27956-PoC, RCE

PoC: CVE-2024-27956

CVE-2024-27956 RCE POC WordPress

PoC: CVE-2024-27956

CVE-2024-27956

PoC: CVE-2024-27956-WORDPRESS-RCE-PLUGIN

CVE-2024-27956 WORDPRESS RCE PLUGIN

PoC: CVE-2024-27956-RCE

PoC for wordpress takeover in CVE-2024-27956

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free