CVE-2024-27956Active Exploitation

LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

3.5/ 10 priority

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-18: 1Mentions · 2026-07-18: 1Active Exploitation · 2026-06-18: 1Technical Details · 2026-06-18: 1Technical Details · 2026-07-18: 106-1807-18
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-181
Active Exploitation1
2026-07-181
Disclosure1
Full discourse2 posts
  • nksistemas@nksistemas
    Disclosure

    CVE-2024-27956: La Crítica Vulnerabilidad wp2shell RCE que Amenaza la Seguridad de WordPress https://nksistemas.com/cve-2024-27956-la-critica-vulnerabilidad-wp2shell-rce-que-amenaza-la-seguridad-de-wordpress/

    Post summary

    The article announces CVE-2024-27956, a critical WordPress RCE vulnerability named wp2shell.

    00000204
    6.2K followersView on X
  • zerizeri(インフラエンジニア技術ブログ)@zerizerizeri_bl
    Active Exploitation

    【WAFログ速報】 136.111.157.119(2回): SQLインジェクション攻撃。UNION SELECTや遅延注入でDB情報窃取を狙う試行が確認された。 /inc/csv.phpのため、WordPress AutomaticプラグインのSQLインジェクション脆弱性(CVE-2024-27956)を狙った攻撃の可能性が高い。 #WAF #セキュリティ #脅威検知

    Post summary

    The WAF log confirms multiple SQL injection attempts from a single IP targeting the WordPress Automatic plugin’s CVE‑2024‑27956, evidencing active exploitation of the vulnerability.

    0000058
    48 followersView on X

Explore more