CVE-2024-11613Disclosure(iptanus / wordpress_file_upload)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wordpress_file_upload

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
wordpress_file_upload

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2024-11613: WordPress File Upload <= 4.24.15... Unauthenticated RCE through unsanitized 'source' param in wfu_file_downloader.php - 9.8 CVSS means instant shells on 10... https://zerodaysignal.com/vulnerability/CVE-2024-11613 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a critical RCE flaw in WordPress File Upload plugin (<=4.24.15) with a CVSS of 9.8, linking to a detailed write‑up, but it does not mention exploitation, patching, or PoC code.

    0000032
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiptanuswordpress_file_upload-wordpress-

Explore more