CVE-2024-56064PoC

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-14: 1Exploit Tool / Code · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2024-56064 - critical 🚨 WP SuperBackup &lt;= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE &gt; The Super Backup &amp; Clone - Migrate for WordPress plugin (indeed-wp-superbackup) is vu... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-56064 @pdnuclei #NucleiTempl...

    Post summary

    A public PoC and Nuclei template for CVE‑2024‑56064 (unauthenticated file upload leading to RCE in WP SuperBackup) are shared, but no evidence of active exploitation or patches is provided.

    00000288
    1.2K followersView on X

Explore more