The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.
PoC: CVE-2024-9047
POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11
PoC: WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal
CVE-2024-9047
PoC: CVE-2024-9047
CVE-2024-9047, wfu_file_downloader.php
PoC: CVE-2024-9047-Exploit
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
PoC: CVE-2024-9047-PoC
WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free