Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-32444 — An unauthenticated privilege escalation problem tracked as CVE-2024-32444 (CVSS score: 9.8). | Kitploit
Tools/GitHubGitHub/rxerium/cve-2024-32444
Privilege EscalationVulnerability ScannersExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubrxerium/cve-2024-32444

CVE-2024-32444

An unauthenticated privilege escalation problem tracked as CVE-2024-32444 (CVSS score: 9.8).

View Repository
110 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-32444

As of 24/01/25 this vulnerabiltiy does not have a patch hence this is simply a product detection template as all products associated with the RealHome wordpress theme are vulnerable.

The theme allows users to register new accounts via the inspiry_ajax_register function, however, it does not properly check authorization or implement a nonce validation.

If registration is enabled on the website, attackers can arbitrarily specify their role as "Administrator" in a specially crafted HTTP request to the registration function, essentially bypassing security checks.

Once registered as an administrator, the attacker can subsequently gain full control of the WordPress site, including performing content manipulation, planting scripts, and accessing user or other sensitive data.

How do I run this script?

  1. Download Nuclei from here
  2. Copy the template to your local system
  3. Run the following command: nuclei -u https://yourHost.com -t template.yaml

References

  • https://www.bleepingcomputer.com/news/security/critical-zero-days-impact-premium-wordpress-real-estate-plugins/

Disclaimer

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

Contact

Feel free to reach out to me on Signal.

Download Tool